1. RED TEAM Operator: Windows Evasion Course

    • Buy now
    • Learn more
  2. Intro and Setup

    • Course Introduction
    • Development VM Setup
    • RTO-WinEva.ova
    • WEv.zip
    • Shellcodes
  3. Essentials

    • Modern Detection Tech
    • Evasion Development Rules
    • Binary Entropy
    • Module Details
    • Binary Signature
  4. Non-privileged user vector

    • Introduction To Process Unhooking
    • Hooks vs Code Injection
    • Process Unhooking - "Classic"
    • Hooks vs Hell's Gate
    • Hooks vs Halo's Gate
    • Process Unhooking - Perun's Fart
    • Silencing Process Event Tracing
    • Module Stomping
    • No-New-Thread Payload Execution
    • "Classic" PPID Spoofing
    • Changing Parents - Scheduler
    • Changing Parents - Emotet Method
    • Cmdline Arguments Spoofing
    • Assignment #1 - Hooks
    • Assignment #2 - Module Stomping
  5. High-privileged user vector

    • Blinding Eventlog
    • Blocking EPP Comms - Listing Connections
    • Blocking EPP Comms - Firewall
    • Blocking EPP Comms - Routing Table (P1)
    • Blocking EPP Comms - Routing Table (P2)
    • Dancing with Sysmon - Detection
    • Dancing with Sysmon - Kill'em!
    • Dancing with Sysmon - Silent Gag
    • Assignment #3 - Sysmon
    • Assignment #4 - Sysmon
  6. Summary

    • Evasion Decision Tree
    • Closing Words
  1. Products
  2. Course
  3. Section

High-privileged user vector

  1. RED TEAM Operator: Windows Evasion Course

    • Buy now
    • Learn more
  2. Intro and Setup

    • Course Introduction
    • Development VM Setup
    • RTO-WinEva.ova
    • WEv.zip
    • Shellcodes
  3. Essentials

    • Modern Detection Tech
    • Evasion Development Rules
    • Binary Entropy
    • Module Details
    • Binary Signature
  4. Non-privileged user vector

    • Introduction To Process Unhooking
    • Hooks vs Code Injection
    • Process Unhooking - "Classic"
    • Hooks vs Hell's Gate
    • Hooks vs Halo's Gate
    • Process Unhooking - Perun's Fart
    • Silencing Process Event Tracing
    • Module Stomping
    • No-New-Thread Payload Execution
    • "Classic" PPID Spoofing
    • Changing Parents - Scheduler
    • Changing Parents - Emotet Method
    • Cmdline Arguments Spoofing
    • Assignment #1 - Hooks
    • Assignment #2 - Module Stomping
  5. High-privileged user vector

    • Blinding Eventlog
    • Blocking EPP Comms - Listing Connections
    • Blocking EPP Comms - Firewall
    • Blocking EPP Comms - Routing Table (P1)
    • Blocking EPP Comms - Routing Table (P2)
    • Dancing with Sysmon - Detection
    • Dancing with Sysmon - Kill'em!
    • Dancing with Sysmon - Silent Gag
    • Assignment #3 - Sysmon
    • Assignment #4 - Sysmon
  6. Summary

    • Evasion Decision Tree
    • Closing Words

10 Lessons
    • Blinding Eventlog
    • Blocking EPP Comms - Listing Connections
    • Blocking EPP Comms - Firewall
    • Blocking EPP Comms - Routing Table (P1)
    • Blocking EPP Comms - Routing Table (P2)
    • Dancing with Sysmon - Detection
    • Dancing with Sysmon - Kill'em!
    • Dancing with Sysmon - Silent Gag
    • Assignment #3 - Sysmon
    • Assignment #4 - Sysmon