{"enrichment":{"faq":[{"a":"Av Edr Evasion teaches authorized penetration testers documented methods to evade antivirus and EDR systems. The skill covers custom DLL and EXE compilation using mingw and Go, AMSI bypass for PowerShell, shellcode alternatives, and ETW patching. These techniques are designed to help security professionals understand how payloads can bypass detection during authorized testing engagements.","q":"What antivirus evasion techniques does Av Edr Evasion cover?"},{"a":"Av Edr Evasion provides instruction on EDR bypass methods grounded in documented techniques. The skill teaches endpoint detection response evasion through multiple approaches including custom payload compilation, AMSI bypass mechanisms, and ETW patching. All content is framed for authorized penetration testers conducting legitimate security research and red team exercises.","q":"How can I bypass EDR detection with Av Edr Evasion?"},{"a":"Av Edr Evasion equips security testers with resources for authorized testing, including compilation frameworks like mingw and Go for custom payloads, AMSI bypass techniques for PowerShell environments, and ETW patching methods. The skill stops before C2 setup or persistence, focusing on the evasion layer of penetration testing workflows.","q":"What tools and resources does Av Edr Evasion provide for security testing?"},{"a":"Yes, Av Edr Evasion helps security professionals understand endpoint detection and response bypass methods to identify defensive gaps. By learning how evasion techniques work, defenders can improve their detection capabilities and strengthen their security posture against these documented attack vectors.","q":"Is Av Edr Evasion suitable for analyzing defensive security gaps?"},{"a":"Av Edr Evasion is released under GPL-3.0 licensing, ensuring the skill and its materials remain open and freely available for authorized security research and testing purposes.","q":"What licensing applies to Av Edr Evasion?"}],"shadow_tags":["security-evasion","threat-research","detection-avoidance","offensive-security","endpoint-hardening","malware-analysis","red-team-tools","vulnerability-assessment"],"summary_rewrite":"This skill teaches authorized penetration testers how to evade antivirus and EDR systems blocking payload execution. It covers custom DLL and EXE compilation using mingw and Go, AMSI bypass for PowerShell, shellcode alternatives, and ETW patching\u2014all grounded in documented techniques and stopping before C2 setup or persistence."},"gist":{"api_url":"https://skillfed.io/api/skills/blacklanternsecurity/red-run/av-edr-evasion.json","as_of":"2026-04-01","description":"Av Edr Evasion teaches custom payload compilation and runtime detection bypass for authorized security.","install":{"manual":["git clone https://github.com/blacklanternsecurity/red-run","cp -r red-run ~/.claude/skills/av-edr-evasion"],"primary":"npx skillfed install blacklanternsecurity/red-run/av-edr-evasion","version":"c1f3e748"},"kind":"skill","mirror_url":"https://skillfed.io/blacklanternsecurity/red-run/av-edr-evasion.md","similar":[{"id":"yaklang/hack-skills/windows-av-evasion","name":"windows-av-evasion","publisher":"yaklang/hack-skills","url":"https://skillfed.io/yaklang/hack-skills/windows-av-evasion"},{"id":"hypnguyen1209/offensive-claude/edr-evasion","name":"edr-evasion","publisher":"hypnguyen1209/offensive-claude","url":"https://skillfed.io/hypnguyen1209/offensive-claude/edr-evasion"},{"id":"hypnguyen1209/offensive-claude/windows-mitigations","name":"windows-mitigations-bypass","publisher":"hypnguyen1209/offensive-claude","url":"https://skillfed.io/hypnguyen1209/offensive-claude/windows-mitigations"},{"id":"blacklanternsecurity/red-run/windows-kernel-exploits","name":"Windows Kernel Exploits","publisher":"blacklanternsecurity/red-run","url":"https://skillfed.io/blacklanternsecurity/red-run/windows-kernel-exploits"},{"id":"hypnguyen1209/offensive-claude/privesc-windows","name":"privesc-windows","publisher":"hypnguyen1209/offensive-claude","url":"https://skillfed.io/hypnguyen1209/offensive-claude/privesc-windows"}],"title":"Av Edr Evasion by blacklanternsecurity \u2014 SkillFed","use":{"when":["Av Edr Evasion provides instruction on EDR bypass methods grounded in documented techniques.","Av Edr Evasion equips security testers with resources for authorized testing."]},"what":{"lead":"Av Edr Evasion teaches custom payload compilation and runtime detection bypass for authorized security testing.","rest":"This skill teaches authorized penetration testers how to evade antivirus and EDR systems blocking payload execution. It covers custom DLL and EXE compilation using mingw and Go, AMSI bypass for PowerShell, shellcode alternatives, and ETW patching\u2014all grounded in documented techniques and stopping before C2 setup or persistence."}},"id":"blacklanternsecurity/red-run/av-edr-evasion","install":{"mode":"external","repo":"https://github.com/blacklanternsecurity/red-run"},"links":{"html":"https://skillfed.io/blacklanternsecurity/red-run/av-edr-evasion","md":"https://skillfed.io/blacklanternsecurity/red-run/av-edr-evasion.md","repo":"https://github.com/blacklanternsecurity/red-run"},"meta":{"agents_supported":[],"first_seen":"2026-07-28","forks":34,"language":"Python","last_updated":"2026-04-01","license":"GPL-3.0","name":"Av Edr Evasion","publisher":"blacklanternsecurity","stars":241},"relations":{"similar":[{"id":"yaklang/hack-skills/windows-av-evasion"},{"id":"hypnguyen1209/offensive-claude/red-team-ops"},{"id":"hypnguyen1209/offensive-claude/edr-evasion"},{"id":"hypnguyen1209/offensive-claude/windows-mitigations"},{"id":"blacklanternsecurity/red-run/windows-service-dll-abuse"},{"id":"zebbern/claude-code-guide/windows-privilege-escalation"},{"id":"hypnguyen1209/offensive-claude/initial-access"},{"id":"blacklanternsecurity/red-run/windows-kernel-exploits"},{"id":"hypnguyen1209/offensive-claude/privesc-windows"},{"id":"hypnguyen1209/offensive-claude/windows-boundaries"}]},"slug":{"owner":"blacklanternsecurity","repo":"red-run","skill":"av-edr-evasion"},"version":"c1f3e748"}
