<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>EDRBypass on Vanilla InfoSec</title>
    <link>/tags/edrbypass/</link>
    <description>Recent content in EDRBypass on Vanilla InfoSec</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en</language>
    <lastBuildDate>Mon, 29 Jun 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="/tags/edrbypass/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>BelphC2 - C2 Comms Via Youtube Comments</title>
      <link>/posts/belphc2---c2-comms-via-youtube-comments/</link>
      <pubDate>Mon, 29 Jun 2026 00:00:00 +0000</pubDate>
      <guid>/posts/belphc2---c2-comms-via-youtube-comments/</guid>
      <description>LOTs &amp;amp; Unconventional Communications A couple years ago I discovered the LOTS project, around when I started learning about GTFOBins and LOLBAS:&#xA;https://lots-project.com/ Living Off Trusted Sites (LOTS) Project Attackers are using popular legitimate domains when conducting phishing, C&amp;amp;C, exfiltration and downloading tools to evade detection. The list of websites below allow attackers to use their domain or subdomain. Website design credits: LOLBAS &amp;amp; GTFOBins&#xA;When preparing for my talk at OISC discussing defense evasion, this struck me as a perfect technique to capture the attention of the audience and hit the points home!</description>
    </item>
  </channel>
</rss>
