diff --git a/Offensive.md b/Offensive.md index 92d4c0e..097b505 100644 --- a/Offensive.md +++ b/Offensive.md @@ -1082,6 +1082,10 @@ Some tools can be categorized in more than one category. But because the current fireeye/OfficePurge VBA purge your Office documents with OfficePurge. VBA purging removes P-code from module streams within Office documents. + + Flangvik/AMSI.fail + C# Azure Function with an HTTP trigger that generates obfuscated PowerShell snippets that break or disable AMSI for the current process. + GetRektBoy724/TripleS Syscall Stub Stealer - Freshly steal Syscall stub straight from the disk