Port 22

'Blindside' Attack Subverts EDR Platforms from Windows Kernel

The technique loads a non-monitored and unhooked DLL, and leverages debug techniques that could allow for running arbitrary code.