{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2024:3EXWLNXGZDFH7XG7WP7IJRYZV2","short_pith_number":"pith:3EXWLNXG","schema_version":"1.0","canonical_sha256":"d92f65b6e6c8ca7fdcdfb3fe84c719ae8a4d84d1c74f4798e47c0d87799f0df9","source":{"kind":"arxiv","id":"2404.16856","version":3},"attestation_state":"computed","paper":{"title":"HookChain: A new perspective for Bypassing EDR Solutions","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.NI","cs.OS"],"primary_cat":"cs.CR","authors_text":"Helvio Carvalho Junior","submitted_at":"2024-04-04T11:44:08Z","abstract_excerpt":"In the current digital security ecosystem, where threats evolve rapidly and with complexity, companies developing Endpoint Detection and Response (EDR) solutions are in constant search for innovations that not only keep up but also anticipate emerging attack vectors. In this context, this article introduces the HookChain, a look from another perspective at widely known techniques, which when combined, provide an additional layer of sophisticated evasion against traditional EDR systems. Through a precise combination of IAT Hooking techniques, dynamic SSN resolution, and indirect system calls, H"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2404.16856","kind":"arxiv","version":3},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2024-04-04T11:44:08Z","cross_cats_sorted":["cs.NI","cs.OS"],"title_canon_sha256":"c8447c35b20bc8ff719213a275044d0b1502f6d135419a8dc24327d55cd04ea7","abstract_canon_sha256":"51b7bd61670f7598e969566abc325b64ca21c05ca9c5e65c725af997345033ef"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T08:56:19.276690Z","signature_b64":"d2VhejDS20JNwGJpNTR04Hv1Z8AjrJ3O5VXYTn6Tu0UjZ1+sjF48QnuBywQgcxpQuiNGFwItoUVH0FXwZLnFCw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"d92f65b6e6c8ca7fdcdfb3fe84c719ae8a4d84d1c74f4798e47c0d87799f0df9","last_reissued_at":"2026-07-05T08:56:19.276267Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T08:56:19.276267Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"HookChain: A new perspective for Bypassing EDR Solutions","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.NI","cs.OS"],"primary_cat":"cs.CR","authors_text":"Helvio Carvalho Junior","submitted_at":"2024-04-04T11:44:08Z","abstract_excerpt":"In the current digital security ecosystem, where threats evolve rapidly and with complexity, companies developing Endpoint Detection and Response (EDR) solutions are in constant search for innovations that not only keep up but also anticipate emerging attack vectors. In this context, this article introduces the HookChain, a look from another perspective at widely known techniques, which when combined, provide an additional layer of sophisticated evasion against traditional EDR systems. Through a precise combination of IAT Hooking techniques, dynamic SSN resolution, and indirect system calls, H"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2404.16856","kind":"arxiv","version":3},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2404.16856/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2404.16856","created_at":"2026-07-05T08:56:19.276332+00:00"},{"alias_kind":"arxiv_version","alias_value":"2404.16856v3","created_at":"2026-07-05T08:56:19.276332+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2404.16856","created_at":"2026-07-05T08:56:19.276332+00:00"},{"alias_kind":"pith_short_12","alias_value":"3EXWLNXGZDFH","created_at":"2026-07-05T08:56:19.276332+00:00"},{"alias_kind":"pith_short_16","alias_value":"3EXWLNXGZDFH7XG7","created_at":"2026-07-05T08:56:19.276332+00:00"},{"alias_kind":"pith_short_8","alias_value":"3EXWLNXG","created_at":"2026-07-05T08:56:19.276332+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2511.04472","citing_title":"Evading and crashing anti-malware solutions via data collection overloading during analysis serialization","ref_index":9,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/3EXWLNXGZDFH7XG7WP7IJRYZV2","json":"https://pith.science/pith/3EXWLNXGZDFH7XG7WP7IJRYZV2.json","graph_json":"https://pith.science/api/pith-number/3EXWLNXGZDFH7XG7WP7IJRYZV2/graph.json","events_json":"https://pith.science/api/pith-number/3EXWLNXGZDFH7XG7WP7IJRYZV2/events.json","paper":"https://pith.science/paper/3EXWLNXG"},"agent_actions":{"view_html":"https://pith.science/pith/3EXWLNXGZDFH7XG7WP7IJRYZV2","download_json":"https://pith.science/pith/3EXWLNXGZDFH7XG7WP7IJRYZV2.json","view_paper":"https://pith.science/paper/3EXWLNXG","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2404.16856&json=true","fetch_graph":"https://pith.science/api/pith-number/3EXWLNXGZDFH7XG7WP7IJRYZV2/graph.json","fetch_events":"https://pith.science/api/pith-number/3EXWLNXGZDFH7XG7WP7IJRYZV2/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/3EXWLNXGZDFH7XG7WP7IJRYZV2/action/timestamp_anchor","attest_storage":"https://pith.science/pith/3EXWLNXGZDFH7XG7WP7IJRYZV2/action/storage_attestation","attest_author":"https://pith.science/pith/3EXWLNXGZDFH7XG7WP7IJRYZV2/action/author_attestation","sign_citation":"https://pith.science/pith/3EXWLNXGZDFH7XG7WP7IJRYZV2/action/citation_signature","submit_replication":"https://pith.science/pith/3EXWLNXGZDFH7XG7WP7IJRYZV2/action/replication_record"}},"created_at":"2026-07-05T08:56:19.276332+00:00","updated_at":"2026-07-05T08:56:19.276332+00:00"}