๐Ÿ”ฎ
Book of Spells
Ctrlk
  • ๐Ÿ•ฏ๏ธREADME
  • ๐Ÿ“ŸPENTEST
    • WI-FI
    • INFRA
    • PERIMETER
    • WEB
    • PRIVESC
    • PERSIST
    • PIVOTING
    • MOBILE
  • ๐Ÿ’€RED TEAM
    • AV / EDR Evasion
      • Powershell
      • Generate shellcode from Go bins
      • Firewall
      • .NET Execute Assembly
      • Defender
      • VMProtect + Res spoof
      • EDR bypass
      • AMSI
      • Logs
    • Maldev
    • C2
    • Living of the land
  • ๐Ÿ“œADMINISTRATION
    • Kafka
    • Powershell
    • DATABASES
    • Linux
    • Gitlab
    • Docker
    • BashWars
    • Certs
    • Networks
    • MONITORING
    • KUBER
    • CTFd
  • web3
    • Solidity
    • Smart contracts vulnerabilities
    • Blockchain
Powered by GitBook
On this page
  1. ๐Ÿ’€RED TEAM
  2. AV / EDR Evasion

EDR bypass

Direct syscalls:

LogoGitHub - ymmfty0/PESyscallGitHub

Syscall numbers

Some methods:

https://pre.empt.blog/2023/maelstrom-5-edr-kernel-callbacks-hooks-and-call-stacks

PreviousVMProtect + Res spoofNextAMSI

Last updated 7 months ago