{"enrichment":{"faq":[{"a":"edr-evasion teaches defensive bypass methods used in red team engagements, including userland hook removal, direct syscall execution, AMSI patching, and memory encryption. The skill explains how EDRs monitor endpoints and covers evasion techniques such as PPID spoofing, process injection variants, and ETW patching to help operators understand detection mechanisms and bypass strategies.","q":"What EDR bypass techniques does edr-evasion cover?"},{"a":"edr-evasion addresses antivirus evasion through multiple layers: hook unhooking to bypass ntdll monitoring, direct and indirect syscall execution to avoid userland API hooks, AMSI bypass for PowerShell obfuscation, and memory encryption combined with sleep masking. The skill also covers behavioral evasion and sandbox detection techniques to help red teams deliver payloads that avoid signature and heuristic detection.","q":"How to evade antivirus detection with edr-evasion?"},{"a":"edr-evasion covers multiple process injection variants including APC injection with early bird techniques, thread pool injection into remote processes, phantom DLL hollowing, and module stomping for shellcode execution. These methods are designed to evade endpoint detection by executing code in legitimate processes while avoiding behavioral monitoring and memory scanning by EDR solutions.","q":"What process injection methods are covered in edr-evasion?"},{"a":"Yes. edr-evasion provides detailed coverage of hook unhooking techniques including ntdll fresh copy methods and direct versus indirect syscall execution on Windows. The skill explains syscall obfuscation approaches and stack spoofing to manipulate return addresses, helping red teamers bypass EDR hooks and execute system calls without triggering detection.","q":"Does edr-evasion explain hook unhooking and syscall obfuscation?"},{"a":"edr-evasion covers advanced tactics including ETW patching for event tracing evasion, sleep masking with beacon encryption, PPID spoofing to spoof parent process IDs, kernel callback removal via BYOVD (Bring Your Own Vulnerable Driver), and Windows 11-specific EDR evasion methods. These techniques target both userland and kernel-level monitoring to achieve comprehensive endpoint evasion.","q":"What advanced evasion tactics does edr-evasion teach?"},{"a":"edr-evasion is designed specifically for red team operations, focusing on evasive payload delivery methods. It teaches how to develop payloads that bypass endpoint detection through behavioral evasion, sandbox detection, memory encryption, and multiple injection techniques. The skill combines userland and kernel-level evasion strategies to help operators deliver implants that avoid EDR and antivirus detection.","q":"Is edr-evasion suitable for red team payload delivery?"}],"shadow_tags":["userland-hooking","kernel-callbacks","syscall-obfuscation","code-injection","memory-protection","sandbox-evasion","stack-manipulation","driver-exploitation","thread-pool-abuse","endpoint-detection-response"],"summary_rewrite":"EDR Evasion covers defensive bypass methods used in red team engagements, from userland hook removal and direct syscall execution to AMSI patching and memory encryption. Learn how EDRs monitor endpoints and the techniques\u2014including PPID spoofing, process injection variants, and ETW patching\u2014that evade their detection."},"files":[{"bytes":21743,"path":"skills/edr-evasion/SKILL.md","sha256":"0226ace5db65dfeffe0b746ee719e9bab2b165d2c67cd9d897a959606ea2d6c7","url":"https://skillfed.io/files/hypnguyen1209/offensive-claude/edr-evasion/6e445bf0/SKILL.md"}],"id":"hypnguyen1209/offensive-claude/edr-evasion","links":{"html":"https://skillfed.io/hypnguyen1209/offensive-claude/edr-evasion","md":"https://skillfed.io/hypnguyen1209/offensive-claude/edr-evasion.md","repo":"https://github.com/hypnguyen1209/offensive-claude"},"meta":{"agents_supported":[],"first_seen":"2026-07-28","forks":58,"language":"Python","last_updated":"2026-07-03","license":"MIT","name":"edr-evasion","publisher":"hypnguyen1209","stars":326},"relations":{"similar":[{"id":"hypnguyen1209/offensive-claude/shellcode-dev"},{"id":"yaklang/hack-skills/windows-av-evasion"},{"id":"blacklanternsecurity/red-run/av-edr-evasion"},{"id":"wshobson/agents/memory-forensics"},{"id":"hypnguyen1209/offensive-claude/red-team-ops"},{"id":"hypnguyen1209/offensive-claude/windows-mitigations"},{"id":"hypnguyen1209/offensive-claude/advanced-redteam"},{"id":"blacklanternsecurity/red-run/windows-kernel-exploits"},{"id":"hypnguyen1209/offensive-claude/keylogger-arch"},{"id":"hypnguyen1209/offensive-claude/malware-analysis"}]},"slug":{"owner":"hypnguyen1209","repo":"offensive-claude","skill":"edr-evasion"},"version":"6e445bf0"}
