A list of tools to bypass EDR using a variety of evasion techniques.
PwnPowerShell
- GH - Signed - https://github.com/sp00ks-git/obfuscated-Encrypted-2023/raw/gh-pages/pjutvtn.exe.Signed.exe
- MU - Signed - https://mega.nz/file/e2gwGIJS#ivCiaYAmi_w_PZz5EPGrehJ2GPlUgEOY1kNphx0nkeQ
- GH - Un-Signed - https://github.com/sp00ks-git/obfuscated-Encrypted-2023/blob/gh-pages/InteractivePS-defender-clean.exe
- MU - Un-Signed - https://mega.nz/file/e2gwGIJS#ivCiaYAmi_w_PZz5EPGrehJ2GPlUgEOY1kNphx0nkeQ
Rubeus
- GH - Rubeus hardcoded with “kerberoast” signed binary - https://github.com/sp00ks-git/obfuscated-Encrypted-2023/raw/gh-pages/bsomtsssohk.exe.Signed.exe
CONTRIBUTORS
Thanks to:
NimSysCallPacker - S3cur3Th1sSh1t @S3cur3Th1sSh1t