diff --git a/Offensive.md b/Offensive.md index ff9daa9..8fbc5cb 100644 --- a/Offensive.md +++ b/Offensive.md @@ -1331,6 +1331,10 @@ Some tools can be categorized in more than one category. But because the current med0x2e/SigFlip SigFlip is a tool for patching authenticode signed PE files (exe, dll, sys ..etc) without invalidating or breaking the existing signature. + + mgeeky/ShellcodeFluctuation + An in-memory evasion technique fluctuating shellcode memory protection between RW & RX and encrypting/decrypting contents + mgeeky/Stracciatella OpSec-safe Powershell runspace from within C# (aka SharpPick) with AMSI, Constrained Language Mode and Script Block Logging disabled at startup @@ -1423,7 +1427,6 @@ Some tools can be categorized in more than one category. But because the current secretsquirrel/SigThief Stealing Signatures and Making One Invalid Signature at a Time - sinfulz/JustEvadeBro JustEvadeBro, a cheat sheet which will aid you through AMSI/AV evasion & bypasses.