diff --git a/Offensive.md b/Offensive.md index 1616267..96e87ee 100644 --- a/Offensive.md +++ b/Offensive.md @@ -454,6 +454,10 @@ Some tools can be categorized in more than one category. But because the current boku7/HOLLOW EarlyBird process hollowing technique (BOF) - Spawns a process in a suspended state, inject shellcode, hijack main thread with APC, and execute shellcode + + boku7/spawn + Cobalt Strike BOF that spawns a sacrificial process, injects it with shellcode, and executes payload. Built to evade EDR/UserLand hooks by spawning sacrificial process with Arbitrary Code Guard (ACG), BlockDll, and PPID spoofing. + Cybellum/DoubleAgent DoubleAgent is a new Zero-Day technique for injecting code and maintaining persistence on a machine (i.e.