From d4e1350b1c48506c365090b7cc1a2553b2573181 Mon Sep 17 00:00:00 2001 From: pe3zx Date: Sun, 7 Aug 2022 10:12:36 +0700 Subject: [PATCH] Add: janoglezcampos/DeathSleep to Defense Evasion --- Offensive.md | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/Offensive.md b/Offensive.md index fd6e59a..cc0c072 100644 --- a/Offensive.md +++ b/Offensive.md @@ -1528,6 +1528,10 @@ Some tools can be categorized in more than one category. But because the current iomoath/PowerShx Run Powershell without software restrictions. + + janoglezcampos/DeathSleep + A PoC implementation for an evasion technique to terminate the current thread and restore it before resuming execution, while implementing page protection changes during no execution. + jason-klein/signed-nsis-exe-append-payload Append a custom data payload to a digitally signed NSIS .exe installer