11/28/2025
EVADING MICROSOFT DEFENDER – APC Injection via Alertable State
We just published a new video demo from RBT Security Labs, showing how Asynchronous Procedure Call (APC) injection can be used to execute code through a thread in an alertable state and how this technique can evade Microsoft Defender.
For this demo, we also highlight related Mythic capabilities, such as AMSI and ETW bypass concepts, default process swapping (e.g., MSBuild.exe as LOLBins), and user-focused system enumeration (Seatbelt) to provide context on how defenders and researchers study post-exploitation techniques.
🎥 Watch the video here: https://www.youtube.com/watch?v=5pMfv2fFDFg&t=17s
Join the Discord community to discuss and learn more: https://discord.gg/8EfKbmgCAPC Injection via alertable stateIn this video, we explain how Asynchronous ...