Skip to content

Commit 28f7d07

Browse files
authored
Update av-bypass.md
1 parent 02e0bd6 commit 28f7d07

1 file changed

Lines changed: 0 additions & 3 deletions

File tree

src/windows-hardening/av-bypass.md

Lines changed: 0 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1145,7 +1145,6 @@ Sleep(exec_delay_seconds * 1000); // config-controlled delay to outlive sandboxe
11451145
- [simplehook – sample](https://tradecraftgarden.org/simplehook.html)
11461146
- [stackcutting – sample](https://tradecraftgarden.org/stackcutting.html)
11471147
- [Draugr – call-stack spoofing PIC](https://github.com/NtDallas/Draugr)
1148-
11491148
- [Unit42 – New Infection Chain and ConfuserEx-Based Obfuscation for DarkCloud Stealer](https://unit42.paloaltonetworks.com/new-darkcloud-stealer-infection-chain/)
11501149
- [Synacktiv – Should you trust your zero trust? Bypassing Zscaler posture checks](https://www.synacktiv.com/en/publications/should-you-trust-your-zero-trust-bypassing-zscaler-posture-checks.html)
11511150
- [Check Point Research – Before ToolShell: Exploring Storm-2603’s Previous Ransomware Operations](https://research.checkpoint.com/2025/before-toolshell-exploring-storm-2603s-previous-ransomware-operations/)
@@ -1159,12 +1158,10 @@ Sleep(exec_delay_seconds * 1000); // config-controlled delay to outlive sandboxe
11591158
- [Zero Salarium – Countering EDRs With The Backing Of Protected Process Light (PPL)](https://www.zerosalarium.com/2025/08/countering-edrs-with-backing-of-ppl-protection.html)
11601159
- [Zero Salarium – Break The Protective Shell Of Windows Defender With The Folder Redirect Technique](https://www.zerosalarium.com/2025/09/Break-Protective-Shell-Windows-Defender-Folder-Redirect-Technique-Symlink.html)
11611160
- [Microsoft – mklink command reference](https://learn.microsoft.com/windows-server/administration/windows-commands/mklink)
1162-
11631161
- [Check Point Research – Under the Pure Curtain: From RAT to Builder to Coder](https://research.checkpoint.com/2025/under-the-pure-curtain-from-rat-to-builder-to-coder/)
11641162
- [Rapid7 – SantaStealer is Coming to Town: A New, Ambitious Infostealer](https://www.rapid7.com/blog/post/tr-santastealer-is-coming-to-town-a-new-ambitious-infostealer-advertised-on-underground-forums)
11651163
- [ChromElevator – Chrome App Bound Encryption Decryption](https://github.com/xaitax/Chrome-App-Bound-Encryption-Decryption)
11661164
- [Check Point Research – GachiLoader: Defeating Node.js Malware with API Tracing](https://research.checkpoint.com/2025/gachiloader-node-js-malware-with-api-tracing/)
1167-
11681165
- [Sleeping Beauty: Putting Adaptix to Bed with Crystal Palace](https://maorsabag.github.io/posts/adaptix-stealthpalace/sleeping-beauty/)
11691166
- [Ekko sleep obfuscation](https://github.com/Cracked5pider/Ekko)
11701167

0 commit comments

Comments
 (0)