vs EDR
WPF abuse to silence an agent
- EDRPrison: https://github.com/senzee1984/EDRPrison, https://www.3nailsinfosec.com/post/edrprison-borrow-a-legitimate-driver-to-mute-edr-agent
- EDRSilencer: https://github.com/netero1010/EDRSilencer,detection: https://mahmoudelfawair.me/posts/theazurelabdiariesdetectingedrsilencers/
- https://github.com/loosehose/SilentButDeadly