PowerShell

Windows Privesc

AMSI and Windows Defender Bypass: A Practical Primer

A hands-on primer on AMSI patching, reflection, obfuscation, and in-memory bypasses, with blue-team detection guidance.
Windows Privesc

PowerShell Obfuscation and Execution Policy Bypass

How attackers bypass PowerShell ExecutionPolicy and CLM with obfuscation, and how defenders detect and stop it.