
kurasagi
Windows 11 24H2-25H2 Runtime PatchGuard Bypass
adversarial-attackbinary-exploitationeducation+4
2659 months ago

Windows 11 24H2-25H2 Runtime PatchGuard Bypass

A technique that can be used to bypass AV/EDR memory scanners. This can be used to hide well-known and detected shellcodes (such as msfvenom) by…

This is the tool to dump the LSASS process on modern Windows 11

Hardware Breakpoint (DR0-DR7) based patch-less user-mode hooking & telemetry instrumentation engine (AMSI, WLDP & ETW PoC).