Post cover image

July 28, 2026

Active Call Stack Spoofing: Hiding Syscalls Behind Legitimate Frames

This post is the second part of a series on call stack manipulation. In the first part we covered the basic return address overwrite, where…

By S12 - 0x12Dark Development

14 min read