AMSI Bypass
-
AmsiScanBuffer -
AmsiScanString
ETW Patching
-
EtwEventWrite -
EtwEventRegister
Unhooking / Clean NTDLL
-
GetModuleHandle -
GetProcAddress -
VirtualProtect -
NtProtectVirtualMemory
Debugger Evasion
-
IsDebuggerPresent -
CheckRemoteDebuggerPresent -
NtQueryInformationProcess -
OutputDebugStringA -
NtSetInformationThread -
AddVectoredExceptionHandler