{"enrichment":{"faq":[{"a":"Windows AV/EDR Evasion teaches hands-on bypass techniques for antivirus and endpoint detection systems, including AMSI memory patching, ETW disabling, .NET assembly loading, shellcode execution via callbacks, process injection methods, EDR unhooking with syscalls, and payload encryption to evade signature-based detection.","q":"What windows av evasion techniques does this skill cover?"},{"a":"Windows AV/EDR Evasion covers AMSI bypass through memory patching techniques and ETW disabling methods. The skill teaches how to patch AMSI in memory to prevent script scanning and disable Event Tracing for Windows to avoid behavioral detection during attack operations.","q":"How can I bypass AMSI and ETW on Windows systems?"},{"a":"Windows AV/EDR Evasion covers shellcode execution via callbacks, process injection techniques including process hollowing and early bird APC injection, and module stomping. These methods allow payload delivery while evading signature-based and behavioral detection mechanisms.","q":"What shellcode execution methods are included?"},{"a":"Windows AV/EDR Evasion teaches EDR unhooking with direct syscalls and NTDLL unhooking techniques to bypass endpoint detection and response systems. It covers syscall-level evasion to avoid EDR hooking mechanisms that monitor system calls.","q":"How does Windows AV/EDR Evasion address EDR detection?"},{"a":"Windows AV/EDR Evasion covers payload encryption and obfuscation to evade signature-based detection. The skill teaches how to encrypt payloads so they bypass antivirus signature scanning and behavioral analysis.","q":"What payload obfuscation methods are taught?"},{"a":"Windows AV/EDR Evasion includes constrained language mode bypass techniques alongside .NET assembly loading methods, enabling unrestricted code execution in restricted PowerShell environments while maintaining evasion from detection systems.","q":"Does this skill cover constrained language mode bypass?"}],"shadow_tags":["endpoint-protection","syscall-abuse","memory-injection","behavioral-evasion","threat-actor-tradecraft","post-exploitation","kernel-bypass","c2-framework-integration"],"summary_rewrite":"Windows AV/EDR Evasion teaches hands-on bypass techniques for antivirus and endpoint detection systems. It covers AMSI memory patching, ETW disabling, .NET assembly loading, shellcode execution via callbacks, process injection methods, EDR unhooking with syscalls, and payload encryption to evade signature-based detection."},"files":[{"bytes":11832,"path":"skills/windows-av-evasion/SKILL.md","sha256":"86506b6e5bf2b6d49b14e0b6c5804ab628fc56f153b12173e2993e5798402c97","url":"https://skillfed.io/files/yaklang/hack-skills/windows-av-evasion/606b7794/SKILL.md"}],"id":"yaklang/hack-skills/windows-av-evasion","links":{"html":"https://skillfed.io/yaklang/hack-skills/windows-av-evasion","md":"https://skillfed.io/yaklang/hack-skills/windows-av-evasion.md","repo":"https://github.com/yaklang/hack-skills"},"meta":{"agents_supported":[],"first_seen":"2026-07-28","forks":196,"language":"CSS","last_updated":"2026-06-16","license":"MIT","name":"windows-av-evasion","publisher":"yaklang","stars":1480},"relations":{"similar":[{"id":"hypnguyen1209/offensive-claude/edr-evasion"},{"id":"hypnguyen1209/offensive-claude/shellcode-dev"},{"id":"blacklanternsecurity/red-run/av-edr-evasion"},{"id":"hypnguyen1209/offensive-claude/red-team-ops"},{"id":"hypnguyen1209/offensive-claude/windows-mitigations"},{"id":"hypnguyen1209/offensive-claude/malware-analysis"},{"id":"hypnguyen1209/offensive-claude/threat-hunting"},{"id":"Unclecheng-li/VulnClaw/redteam-evasion-detail-pack"},{"id":"hypnguyen1209/offensive-claude/keylogger-arch"},{"id":"yaklang/hack-skills/linux-security-bypass"}]},"slug":{"owner":"yaklang","repo":"hack-skills","skill":"windows-av-evasion"},"version":"606b7794"}
