diff --git a/Offensive.md b/Offensive.md index a87772b..4cad3cc 100644 --- a/Offensive.md +++ b/Offensive.md @@ -414,6 +414,10 @@ Some tools can be categorized in more than one category. But because the current boku7/AsmHalosGate x64 Assembly HalosGate direct System Caller to evade EDR UserLand hooks + + boku7/halosgate-ps + Cobalt Strike BOF that uses a custom ASM HalosGate & HellsGate syscaller to return a list of processes + boku7/HOLLOW EarlyBird process hollowing technique (BOF) - Spawns a process in a suspended state, inject shellcode, hijack main thread with APC, and execute shellcode