Attackers with admin access can abuse Windows Bind Links to redirect legitimate file paths to malicious binaries, bypassing EDR, AMSI, and AppLocker controls.
Gentlemen gang uses at least eight variants of GentleKiller to disable EDR protection from 48 different security vendors before executing ransomware attacks.