You are tasked with delivering a Meterpreter payload to a Windows Server 2019 target protected by a next-generation antivirus that performs userland API hooking on NtAllocateVirtualMemory and NtProtectVirtualMemory. Your current C loader uses these APIs directly and is detected. Which technique is most appropriate to bypass the userland hooks without requiring kernel-level privileges?
Manually building the syscall stub bypasses userland hooks because the hook resides in ntdll's exported function, not in the kernel transition path. By placing the syscall number in EAX and executing the syscall instruction directly, the loader skips the modified ntdll code entirely. This works without kernel privileges and is a standard PEN-200 technique for evading EDR hooks on memory allocation and protection APIs.
Why this answer
Direct system calls bypass userland API hooks because the hooks are placed in ntdll's exported functions, and invoking the syscall instruction directly skips that code. The other options either require kernel privileges, still transit the hooked APIs, or only address static detection rather than the behavioral hooks causing the detection.
Exam trap
The trap here is believing that in-memory compilation or payload encryption changes the API call path, when both still invoke the hooked ntdll functions.