Runbooks¶ Step-by-step procedures for individual evasion techniques. Runbooks LoLbin payload execution Reflective PE loading BYOVD: loading a vulnerable driver AMSI bypass Sandbox detection Process injection