TGViewer
P.F.K 0Day P.F.K 0Day @pfk_0day · 1.12K subscribers
Post #46 1.51K
​​EDRSandBlast

EDRSandBlast is a tool written in C that weaponize a vulnerable signed driver to bypass EDR detections (Kernel callbacks and ETW TI provider) and LSASS protections. Multiple userland unhooking techniques are also implemented to evade userland monitoring.

As of release, combination of userland (--usermode) and Kernel-land (--kernelmode) techniques were used to dump LSASS memory under EDR scrutiny, without being blocked nor generating "OS Credential Dumping"-related events in the product (cloud) console. The tests were performed on 3 distinct EDR products and were successful in each case.

https://github.com/wavestone-cdt/EDRSandblast/tree/DefCon30Release

@pfk_0day
GitHub GitHub - wavestone-cdt/EDRSandblast at DefCon30Release Contribute to wavestone-cdt/EDRSandblast development by creating an account on GitHub.
  • 👍 1
More from @pfk_0day
  1. Oct 4, 2026🔥 جشن شهریورگان / ۳۰ امرداد 💠 شهریورگان، جشنی به پاس شهریور امشاسپند است. شهریور، فروزه‌…
  2. Oct 4, 2026⁨ به یاد مردی که نامش با آزادی، خرد، دادگری و بزرگواری در تاریخ ایران جاودانه شد؛ مردی که…
  3. Nov 6, 2025🎓 مرجع تخصصی آموزش تست نفوذ و رد تیم TryHackBox و Ai Security 📌 در اینجا، آموزش‌ های خود…
  4. Sep 30, 2025ADKAVEH — PowerShell tool for AD enumeration & attack simulation ADKAVEH is a PowerShell s…
  5. Apr 19, 2023https://github.com/oldboy21/CGPL
  6. Apr 17, 2023​​pdtm ProjectDiscovery's Open Source Tool Manager A simple and easy-to-use golang based t…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →