drop process memory · detect indirect-syscall trampoline patterns · runs locally
mov r10, rcx · mov eax, SSN · jmp [ntdll+…] · Hell's Gate / SysWhispers-style trampolines
heuristic screener · parses artifacts locally · not definitive proof of syscall evasion