diff --git a/Offensive.md b/Offensive.md index 2b9716e..844d391 100644 --- a/Offensive.md +++ b/Offensive.md @@ -38,6 +38,10 @@ Some tools can be categorized in more than one category. But because the current asaurusrex/Probatorum-EDR-Userland-Hook-Checker Project to check which Nt/Zw functions your local EDR is hooking + + boku7/whereami + Cobalt Strike Beacon Object File (BOF) that uses handwritten shellcode to return the process Environment strings without touching any DLL's. + chdav/SharpCGHunter Receive the status of Windows Defender Credential Guard on network hosts.