diff --git a/Offensive.md b/Offensive.md index db5e5b6..60b5fe3 100644 --- a/Offensive.md +++ b/Offensive.md @@ -1641,6 +1641,10 @@ Some tools can be categorized in more than one category. But because the current Wra7h/Single-Dose Generate process injection binaries + + wavestone-cdt/EdrSandblast + EDRSandBlast is a tool written in C that weaponize a vulnerable signed driver to bypass EDR detections (Kernel callbacks and ETW TI provider) and LSASS protections + xct/morbol Simple AV Evasion for PE Files