diff --git a/Offensive.md b/Offensive.md index d187593..09e0c44 100644 --- a/Offensive.md +++ b/Offensive.md @@ -1129,6 +1129,10 @@ Some tools can be categorized in more than one category. But because the current boku7/injectAmsiBypass Cobalt Strike BOF - Bypass AMSI in a remote process with code injection. + + boku7/injectEtwBypass + CobaltStrike BOF - Inject ETW Bypass into Remote Process via Syscalls (HellsGate|HalosGate) + br-sn/CheekyBlinder Enumerating and removing kernel callbacks using signed vulnerable drivers