From fe833ac19908f9f98d4dd5371955d932e6966488 Mon Sep 17 00:00:00 2001 From: pe3zx Date: Thu, 29 Apr 2021 14:07:55 +0700 Subject: [PATCH] Add: lawiet47/STFUEDR to Defense Evasion section --- Offensive.md | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/Offensive.md b/Offensive.md index 4a241a9..7af4480 100644 --- a/Offensive.md +++ b/Offensive.md @@ -742,6 +742,10 @@ Some tools can be categorized in more than one category. But because the current karttoon/trigen Trigen is a Python script which uses different combinations of Win32 function calls in generated VBA to execute shellcode. + + lawiet47/STFUEDR + Silence EDRs by removing kernel callbacks + matterpreter/DefenderCheck Identifies the bytes that Microsoft Defender flags on.