From abd7e905bc0d2b5aa2de77e457fb1a556f0fbd4f Mon Sep 17 00:00:00 2001 From: pe3zx Date: Wed, 30 Mar 2022 15:06:58 +0700 Subject: [PATCH] Add: waldo-irc/YouMayPasser to Defense Evasion section --- Offensive.md | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/Offensive.md b/Offensive.md index e35e24c..1ddc355 100644 --- a/Offensive.md +++ b/Offensive.md @@ -1845,6 +1845,10 @@ Some tools can be categorized in more than one category. But because the current VirtualAlllocEx/Shellcode-Downloader-CreateThread-Execution This POC gives you the possibility to compile a .exe to completely avoid statically detection by AV/EPP/EDR of your C2-shellcode and download and execute your C2-shellcode which is hosted on your (C2)-webserver. + + waldo-irc/YouMayPasser + YouMayPasser is an x64 implementation of Gargoyle + Wra7h/Single-Dose Generate process injection binaries