Av Edr Evasion
This skill teaches authorized penetration testers how to evade antivirus and EDR systems blocking payload execution. It covers custom DLL and EXE compilation using mingw and Go, AMSI bypass for PowerShell, shellcode alternatives, and ETW patching—all grounded in documented techniques and stopping before C2 setup or persistence.
Av Edr Evasion teaches custom payload compilation and runtime detection bypass for authorized security testing.
AI-generated summary based on this skill's SKILL.md
Decision gist · record as of 2026-04-01
Av Edr Evasion teaches custom payload compilation and runtime detection bypass for authorized security testing. This skill teaches authorized penetration testers how to evade antivirus and EDR systems blocking payload execution. It covers custom DLL and EXE compilation using mingw and Go, AMSI bypass for PowerShell, shellcode alternatives, and ETW patching—all grounded in documented techniques and stopping before C2 setup or persistence.
Use it when
- Av Edr Evasion provides instruction on EDR bypass methods grounded in documented techniques.
- Av Edr Evasion equips security testers with resources for authorized testing.
Install
blacklanternsecurity/red-run/av-edr-evasion · repository language: Python
generated, unverified - the skill's exact subdirectory could not be determined; check the repository on GitHub
Open directory. Skills are indexed for reading, not audited. Review a skill's body before installing it.
Frequently asked questions
AI-generated answers based on this skill's SKILL.md and metadata
What antivirus evasion techniques does Av Edr Evasion cover?
Av Edr Evasion teaches authorized penetration testers documented methods to evade antivirus and EDR systems. The skill covers custom DLL and EXE compilation using mingw and Go, AMSI bypass for PowerShell, shellcode alternatives, and ETW patching. These techniques are designed to help security professionals understand how payloads can bypass detection during authorized testing engagements.
How can I bypass EDR detection with Av Edr Evasion?
Av Edr Evasion provides instruction on EDR bypass methods grounded in documented techniques. The skill teaches endpoint detection response evasion through multiple approaches including custom payload compilation, AMSI bypass mechanisms, and ETW patching. All content is framed for authorized penetration testers conducting legitimate security research and red team exercises.
What tools and resources does Av Edr Evasion provide for security testing?
Av Edr Evasion equips security testers with resources for authorized testing, including compilation frameworks like mingw and Go for custom payloads, AMSI bypass techniques for PowerShell environments, and ETW patching methods. The skill stops before C2 setup or persistence, focusing on the evasion layer of penetration testing workflows.
Is Av Edr Evasion suitable for analyzing defensive security gaps?
Yes, Av Edr Evasion helps security professionals understand endpoint detection and response bypass methods to identify defensive gaps. By learning how evasion techniques work, defenders can improve their detection capabilities and strengthen their security posture against these documented attack vectors.
What licensing applies to Av Edr Evasion?
Av Edr Evasion is released under GPL-3.0 licensing, ensuring the skill and its materials remain open and freely available for authorized security research and testing purposes.
Let your AI agent find skills like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 56,283 agent skills by what they can do, searchable in plain language.
wish › “Learn antivirus and EDR evasion techniques for security research”
Give your agent the search over MCP, or paste the wish link into any chat. No install? Search from any chat →
Related skills
Windows AV/EDR Evasion teaches hands-on bypass techniques for antivirus and endpoint detection systems. It covers AMSI memory patching, ETW disabling, .NET assembly loading, shellcode execution via callbacks, process injection methods, EDR unhooking with syscalls, and payload encryption to evade signature-based detection.
EDR Evasion covers defensive bypass methods used in red team engagements, from userland hook removal and direct syscall execution to AMSI patching and memory encryption. Learn how EDRs monitor endpoints and the techniques—including PPID spoofing, process injection variants, and ETW patching—that evade their detection.
This skill maps techniques for defeating Windows exploit mitigations—memory protections like ASLR, DEP, CFG, and CET—alongside platform security controls including WDAC, ASR, AMSI, ETW, and PPL. It pairs each bypass method with detection signatures and operational security notes to support both offensive testing and defensive hardening. Includes reconnaissance scripts, gadget finders, and a quick-start workflow for fingerprinting a target's mitigation landscape before weaponizing an exploit.
This skill guides penetration testers through identifying and exploiting Windows kernel vulnerabilities for privilege escalation. It covers automated vulnerability assessment using tools like WES-NG and Watson, then walks through exploitation of named CVEs including PrintNightmare, EternalBlue, and others, with emphasis on reliability and crash risk mitigation.
privesc-windows guides you through multiple privilege-escalation paths on Windows hosts, from token-impersonation attacks (GodPotato, SigmaPotato, PrintNotifyPotato) and UAC bypass techniques to service/DLL hijacking and kernel exploits. It covers enumeration, exploitation, and credential harvesting with tactical OPSEC guidance and detection evasion for each method.
Windows Boundaries equips you with techniques and tools to cross Windows security boundaries—from kernel/user mode transitions via win32k/dxgkrnl exploits and BYOVD drivers, to UAC elevation, AppContainer/LPAC sandbox escapes, PPL circumvention, and RPC/ALPC-based token impersonation. Includes enumeration scripts, proof-of-concept exploits, and OPSEC guidance for each attack vector.
More skills Bitdefender Security Analysis (NOASSERTION) · Windows Token Impersonation (GPL-3.0)