Index / Vendors / Microsoft
Product Record

Microsoft

Publicly-reported techniques recorded as bypassing Microsoft. Each entry is sourced to its original disclosure. This is a factual tally, maintained on the same basis for every vendor in the Index.

142
recorded bypasses
20
distinct techniques

Techniques recorded against Microsoft

TechniqueEntriesHigh-confidenceMost recent
AMSI Bypass 34292026-05-21
BYOVD (Vulnerable Driver) 24232026-05-03
Disable or Modify Tools 17162026-05-21
Exploitation for Priv-Esc 982026-05-22
Tamper-Protection Bypass 872026-04-17
Obfuscation / Packing 762026-04-20
Process Injection 642025-08-14
Code-Signing Abuse 552026-05-23
Valid Accounts 442026-05-13
Pre-OS Boot 442025-08-24
DLL Side-Loading 442026-05-11
EDR Unhooking 432025-12-05
LSASS Credential Dumping 332026-05-13
Masquerading 332025-12-28
Indicator Removal 222024-04-22
Rootkit 222026-04-14
Reflective Code Loading 212026-03-29
Direct Syscalls 212026-05-04
ETW Tampering 102026-05-19
Safe-Mode Boot 112024-09-25

All entries

TechniqueConfidenceDisclosedSource
Code-Signing Abuse high 2026-05-23www.positioniseverything.net record →
Exploitation for Priv-Esc medium 2026-05-22Microsoft Threat Intel record →
Disable or Modify Tools high 2026-05-21Huntress record →
AMSI Bypass high 2026-05-21www.tiraniddo.dev record →
Code-Signing Abuse high 2026-05-20cybersecuritynews.com record →
ETW Tampering medium 2026-05-19medium.com record →
Exploitation for Priv-Esc high 2026-05-18thehackernews.com record →
Exploitation for Priv-Esc high 2026-05-18www.csoonline.com record →
AMSI Bypass high 2026-05-16infosecwriteups.com record →
LSASS Credential Dumping high 2026-05-13theregister.com record →
Valid Accounts high 2026-05-13lyrie.ai record →
DLL Side-Loading high 2026-05-11The DFIR Report record →
Direct Syscalls high 2026-05-04hackers-arise.com record →
BYOVD (Vulnerable Driver) high 2026-05-03lyrie.ai record →
LSASS Credential Dumping high 2026-04-27www.persistent-security.net record →
Obfuscation / Packing medium 2026-04-20github.com record →
AMSI Bypass high 2026-04-18medium.com record →
Tamper-Protection Bypass high 2026-04-17gbhackers.com record →
Exploitation for Priv-Esc high 2026-04-17www.cyderes.com record →
Rootkit high 2026-04-14www.gendigital.com record →
Exploitation for Priv-Esc high 2026-04-07www.cyderes.com record →
Reflective Code Loading high 2026-03-29medium.com record →
BYOVD (Vulnerable Driver) high 2026-03-26labs.cloudsecurityalliance.org record →
BYOVD (Vulnerable Driver) high 2026-03-26github.com record →
BYOVD (Vulnerable Driver) high 2026-03-13www.healthcaredive.com record →
DLL Side-Loading high 2026-03-08cybernoz.com record →
AMSI Bypass high 2026-03-05github.com record →
Disable or Modify Tools high 2026-02-27binarydefense.com record →
BYOVD (Vulnerable Driver) high 2026-02-24blog.silentforce.io record →
Tamper-Protection Bypass high 2026-02-19medium.com record →
BYOVD (Vulnerable Driver) high 2026-02-10github.com record →
Obfuscation / Packing high 2026-01-28bloo.io record →
AMSI Bypass high 2026-01-13medium.com record →
Disable or Modify Tools high 2026-01-11cybernoz.com record →
AMSI Bypass high 2026-01-10gist.github.com record →
Masquerading high 2025-12-28medium.com record →
AMSI Bypass high 2025-12-28medium.com record →
EDR Unhooking high 2025-12-05medium.com record →
Obfuscation / Packing high 2025-12-02github.com record →
Disable or Modify Tools high 2025-11-17cyberpress.org record →
AMSI Bypass medium 2025-11-14medium.com record →
BYOVD (Vulnerable Driver) high 2025-11-14gbhackers.com record →
Tamper-Protection Bypass high 2025-11-13err0rgod.medium.com record →
BYOVD (Vulnerable Driver) high 2025-11-10github.com record →
BYOVD (Vulnerable Driver) high 2025-11-07github.com record →
DLL Side-Loading high 2025-11-01cybernoz.com record →
AMSI Bypass high 2025-10-17blog.ukatemi.com record →
Disable or Modify Tools high 2025-10-15windowsforum.com record →
Tamper-Protection Bypass high 2025-10-10labs.infoguard.ch record →
Obfuscation / Packing high 2025-10-01www.noahheraud.com record →
Disable or Modify Tools high 2025-09-29prevent-ransomware.com record →
Reflective Code Loading medium 2025-09-23g3tsyst3m.com record →
BYOVD (Vulnerable Driver) high 2025-08-28radar.offseq.com record →
Disable or Modify Tools high 2025-08-28beierle.win record →
Pre-OS Boot high 2025-08-24github.com record →
Process Injection high 2025-08-14github.com record →
BYOVD (Vulnerable Driver) medium 2025-08-07mine2.io record →
AMSI Bypass high 2025-07-28www.netskope.com record →
AMSI Bypass high 2025-07-23github.com record →
Masquerading high 2025-07-14www.kaspersky.com record →
EDR Unhooking medium 2025-07-13github.com record →
Process Injection high 2025-06-25undercodetesting.com record →
AMSI Bypass high 2025-06-24github.com record →
Code-Signing Abuse high 2025-06-19undercodetesting.com record →
Disable or Modify Tools high 2025-06-15github.com record →
LSASS Credential Dumping high 2025-06-13undercodetesting.com record →
Tamper-Protection Bypass medium 2025-06-12github.com record →
Disable or Modify Tools high 2025-06-10www.linkedin.com record →
Exploitation for Priv-Esc high 2025-06-10cybersecuritynews.com record →
AMSI Bypass high 2025-06-06medium.com record →
AMSI Bypass high 2025-06-03medium.com record →
BYOVD (Vulnerable Driver) high 2025-05-30threatlabsnews.xcitium.com record →
AMSI Bypass medium 2025-05-16shells.systems record →
Exploitation for Priv-Esc high 2025-05-15cybersecuritynews.com record →
AMSI Bypass high 2025-05-12github.com record →
AMSI Bypass high 2025-04-24github.com record →
AMSI Bypass high 2025-04-15github.com record →
Disable or Modify Tools high 2025-04-08www.sentinelone.com record →
BYOVD (Vulnerable Driver) high 2025-03-16asec.ahnlab.com record →
AMSI Bypass medium 2025-03-11github.com record →
AMSI Bypass high 2025-02-28lumu.io record →
BYOVD (Vulnerable Driver) high 2025-01-18www.zerosalarium.com record →
Disable or Modify Tools high 2024-12-01cloudbrothers.info record →
AMSI Bypass high 2024-11-21practicalsecurityanalytics.com record →
AMSI Bypass high 2024-10-20github.com record →
Safe-Mode Boot high 2024-09-25github.com record →
BYOVD (Vulnerable Driver) high 2024-09-18cybersecuritynews.com record →
Exploitation for Priv-Esc high 2024-08-19securityaffairs.com record →
BYOVD (Vulnerable Driver) high 2024-08-18github.com record →
Disable or Modify Tools high 2024-08-11dazzyddos.github.io record →
Code-Signing Abuse high 2024-08-06www.elastic.co record →
AMSI Bypass medium 2024-08-02github.com record →
Pre-OS Boot high 2024-07-17github.com record →
BYOVD (Vulnerable Driver) high 2024-07-16trustedsec.com record →
BYOVD (Vulnerable Driver) high 2024-06-27infosecwriteups.com record →
Obfuscation / Packing high 2024-06-26kaganeglence.com record →
AMSI Bypass high 2024-06-22www.elastic.co record →
Tamper-Protection Bypass high 2024-06-05github.com record →
Disable or Modify Tools high 2024-05-29cybernoz.com record →
Obfuscation / Packing high 2024-05-29www.dotsec.com record →
Valid Accounts high 2024-05-27rootsecdev.medium.com record →
BYOVD (Vulnerable Driver) high 2024-05-27github.com record →
Direct Syscalls medium 2024-05-08github.com record →
AMSI Bypass high 2024-05-04github.com record →
AMSI Bypass high 2024-05-03www.offsec.com record →
Code-Signing Abuse high 2024-04-26vsociety.medium.com record →
Disable or Modify Tools high 2024-04-24gbhackers.com record →
Indicator Removal high 2024-04-22winbuzzer.com record →
Pre-OS Boot high 2024-04-09www.cve.news record →
BYOVD (Vulnerable Driver) high 2024-04-05github.com record →
BYOVD (Vulnerable Driver) high 2024-04-04github.com record →
Disable or Modify Tools high 2024-03-21blog.talosintelligence.com record →
DLL Side-Loading high 2024-03-13cybersecsentinel.com record →
AMSI Bypass medium 2024-03-07github.com record →
Obfuscation / Packing high 2024-02-27github.com record →
Rootkit high 2024-02-25github.com record →
Exploitation for Priv-Esc high 2024-02-07research.checkpoint.com record →
Pre-OS Boot high 2024-02-01blog.compass-security.com record →
AMSI Bypass high 2024-01-21medium.com record →
Valid Accounts high 2024-01-20www.microsoft.com record →
BYOVD (Vulnerable Driver) high 2024-01-12www.trendmicro.com record →
Process Injection high 2023-12-08securityaffairs.com record →
AMSI Bypass high 2023-11-30gist.github.com record →
Process Injection high 2023-11-16chayanin-mews.medium.com record →
Masquerading high 2023-11-11blogs.pivotsec.in record →
Process Injection medium 2023-10-28github.com record →
AMSI Bypass high 2023-10-24github.com record →
Tamper-Protection Bypass high 2023-10-17www.csis.com record →
AMSI Bypass high 2023-10-06github.com record →
Disable or Modify Tools high 2023-09-13labs.infoguard.ch record →
Tamper-Protection Bypass high 2023-09-12www.sentinelone.com record →
AMSI Bypass high 2023-08-28github.com record →
Process Injection medium 2023-08-21github.com record →
BYOVD (Vulnerable Driver) high 2023-08-16jmp-esp.org record →
Indicator Removal high 2023-08-11www.safebreach.com record →
Valid Accounts high 2023-08-08securityboulevard.com record →
AMSI Bypass high 2023-07-19github.com record →
EDR Unhooking high 2023-06-07www.linkedin.com record →
Disable or Modify Tools medium 2023-06-01www.threatlocker.com record →
EDR Unhooking high 2023-06-01github.com record →
AMSI Bypass high 2023-06-01github.com record →
BYOVD (Vulnerable Driver) high 2023-05-31www.bleepingcomputer.com record →

Counts reflect distinct publicly-reported events on record; absence of an entry means no confirmed public report is on file, not that a product is unaffected.