Evasion detection and huntingΒΆ
Runbooks for detecting evasion in practice: LOLbin abuse, fileless execution, bring-your-own-vulnerable-driver attacks, C2 channel identification, and threat hunting workflows for low-and-slow activity that bypasses alert-based detection.
Detection and investigation runbooks: