Bring Your Own Vulnerable Driver
https://www.loldrivers.io/
https://alice.climent-pommeret.red/posts/process-killer-driver/
https://z4ksec.github.io/posts/ioctlhunter-release-v0.2/
[PDF] EDR detection mechanisms and bypass techniques with EDRSandblast (Maxime Meignan, Thomas Diot)
https://github.com/wavestone-cdt/EDRSandblast
https://www.elastic.co/security-labs/forget-vulnerable-drivers-admin-is-all-you-need
https://github.com/gabriellandau/EDRSandblast-GodFault
https://v1k1ngfr.github.io/edrsnowblast/
Wipe kernel callbacks, prevent EDR internal communication, etc.
https://synzack.github.io/Blinding-EDR-On-Windows/
https://sensepost.com/blog/2023/filter-mute-operation-investigating-edr-internal-communication/
https://github.com/Yaxser/Backstab
https://github.com/ZeroMemoryEx/Blackout
https://github.com/ZeroMemoryEx/Terminator
Last updated 2 years ago