> For the complete documentation index, see [llms.txt](https://ppn.snovvcra.sh/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ppn.snovvcra.sh/pentest/infrastructure/ad/av-edr-evasion/byovd.md).

# BYOVD

* <https://www.loldrivers.io/>
* <https://alice.climent-pommeret.red/posts/process-killer-driver/>
* <https://z4ksec.github.io/posts/ioctlhunter-release-v0.2/>

## EDRSandblast

* [\[PDF\] EDR detection mechanisms and bypass techniques with EDRSandblast (Maxime Meignan, Thomas Diot)](https://github.com/wavestone-cdt/EDRSandblast/blob/DefCon30Release/DEFCON30-DemoLabs-EDR_detection_mechanisms_and_bypass_techniques_with_EDRSandblast-v1.0.pdf)
* <https://github.com/wavestone-cdt/EDRSandblast>
* <https://www.elastic.co/security-labs/forget-vulnerable-drivers-admin-is-all-you-need>
* <https://github.com/gabriellandau/EDRSandblast-GodFault>

### EDRSnowblast

* <https://v1k1ngfr.github.io/edrsnowblast/>

## Blinding EDR

**Wipe kernel callbacks, prevent EDR internal communication, etc.**

* <https://synzack.github.io/Blinding-EDR-On-Windows/>
* <https://sensepost.com/blog/2023/filter-mute-operation-investigating-edr-internal-communication/>

## Tools

* <https://github.com/Yaxser/Backstab>
* <https://github.com/ZeroMemoryEx/Blackout>
* <https://github.com/ZeroMemoryEx/Terminator>
