diff --git a/Offensive.md b/Offensive.md index 420fbfc..5776da7 100644 --- a/Offensive.md +++ b/Offensive.md @@ -538,8 +538,11 @@ Some tools can be categorized in more than one category. But because the current mobdk/Sigma - Execute shellcode with ZwCreateSection, ZwMapViewOfSection, ZwOpenProcess, ZwMapViewOfSection and - ZwCreateThreadEx + Execute shellcode with ZwCreateSection, ZwMapViewOfSection, ZwOpenProcess, ZwMapViewOfSection and ZwCreateThreadEx + + + mobdk/Upsilon + Upsilon execute shellcode with syscalls - no API like NtProtectVirtualMemory is used monoxgas/sRDI