diff --git a/Offensive.md b/Offensive.md index 6488157..d52f4b7 100644 --- a/Offensive.md +++ b/Offensive.md @@ -1198,6 +1198,10 @@ Some tools can be categorized in more than one category. But because the current RedCursorSecurityConsulting/PPLKiller Tool to bypass LSA Protection (aka Protected Process Light) + + rmdavy/HeapsOfFun + AMSI Bypass Via the Heap + secretsquirrel/SigThief Stealing Signatures and Making One Invalid Signature at a Time