diff --git a/Offensive.md b/Offensive.md index 6d40130..25d6396 100644 --- a/Offensive.md +++ b/Offensive.md @@ -1178,7 +1178,6 @@ Some tools can be categorized in more than one category. But because the current mdsecactivebreach/firewalker This repo contains a simple library which can be used to add FireWalker hook bypass capabilities to existing code - med0x2e/NoAmci Using DInvoke to patch AMSI.dll in order to bypass AMSI detections triggered when loading .NET tradecraft via Assembly.Load(). @@ -1191,6 +1190,10 @@ Some tools can be categorized in more than one category. But because the current mgeeky/Stracciatella OpSec-safe Powershell runspace from within C# (aka SharpPick) with AMSI, Constrained Language Mode and Script Block Logging disabled at startup + + MinervaLabsResearch/CoffeeShot + CoffeeShot: Avoid Detection with Memory Injection + nccgroup/demiguise HTA encryption tool for RedTeams