EDRSandblast. EDRSandBlast is a tool written in C that weaponize a vulnerable signed driver to bypass EDR detections (Notify Routine callbacks, Object Callbacks and ETW TI provider) and LSASS protections. Multiple userland unhooking techniques are also implemented to evade userland monitoring.

github.com/nuts7/EDRSandblast

Vaya's read on this project

Problem, audience, market, and the verdict — sign in to see it.

Updates

No recent activity.