$npx skillfedfor your agent

Av Edr Evasion

This skill teaches authorized penetration testers how to evade antivirus and EDR systems blocking payload execution. It covers custom DLL and EXE compilation using mingw and Go, AMSI bypass for PowerShell, shellcode alternatives, and ETW patching—all grounded in documented techniques and stopping before C2 setup or persistence.

Av Edr Evasion teaches custom payload compilation and runtime detection bypass for authorized security testing.

AI-generated summary based on this skill's SKILL.md

241 34 GPL-3.0updated by blacklanternsecurity

Decision gist · record as of 2026-04-01

Av Edr Evasion teaches custom payload compilation and runtime detection bypass for authorized security testing. This skill teaches authorized penetration testers how to evade antivirus and EDR systems blocking payload execution. It covers custom DLL and EXE compilation using mingw and Go, AMSI bypass for PowerShell, shellcode alternatives, and ETW patching—all grounded in documented techniques and stopping before C2 setup or persistence.

manual: git clone https://github.com/blacklanternsecurity/red-run → cp -r red-run ~/.claude/skills/av-edr-evasion

Use it when

  • Av Edr Evasion provides instruction on EDR bypass methods grounded in documented techniques.
  • Av Edr Evasion equips security testers with resources for authorized testing.
Same gist for agents: .md · .json

Install

blacklanternsecurity/red-run/av-edr-evasion · repository language: Python

generated, unverified - the skill's exact subdirectory could not be determined; check the repository on GitHub

Open directory. Skills are indexed for reading, not audited. Review a skill's body before installing it.

Frequently asked questions

AI-generated answers based on this skill's SKILL.md and metadata

What antivirus evasion techniques does Av Edr Evasion cover?

Av Edr Evasion teaches authorized penetration testers documented methods to evade antivirus and EDR systems. The skill covers custom DLL and EXE compilation using mingw and Go, AMSI bypass for PowerShell, shellcode alternatives, and ETW patching. These techniques are designed to help security professionals understand how payloads can bypass detection during authorized testing engagements.

How can I bypass EDR detection with Av Edr Evasion?

Av Edr Evasion provides instruction on EDR bypass methods grounded in documented techniques. The skill teaches endpoint detection response evasion through multiple approaches including custom payload compilation, AMSI bypass mechanisms, and ETW patching. All content is framed for authorized penetration testers conducting legitimate security research and red team exercises.

What tools and resources does Av Edr Evasion provide for security testing?

Av Edr Evasion equips security testers with resources for authorized testing, including compilation frameworks like mingw and Go for custom payloads, AMSI bypass techniques for PowerShell environments, and ETW patching methods. The skill stops before C2 setup or persistence, focusing on the evasion layer of penetration testing workflows.

Is Av Edr Evasion suitable for analyzing defensive security gaps?

Yes, Av Edr Evasion helps security professionals understand endpoint detection and response bypass methods to identify defensive gaps. By learning how evasion techniques work, defenders can improve their detection capabilities and strengthen their security posture against these documented attack vectors.

What licensing applies to Av Edr Evasion?

Av Edr Evasion is released under GPL-3.0 licensing, ensuring the skill and its materials remain open and freely available for authorized security research and testing purposes.

Let your AI agent find skills like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 56,283 agent skills by what they can do, searchable in plain language.

wish › “Learn antivirus and EDR evasion techniques for security research”

Give your agent the search over MCP, or paste the wish link into any chat. No install? Search from any chat →

Related skills

windows-av-evasion
by yaklang · yaklang/hack-skills

Windows AV/EDR Evasion teaches hands-on bypass techniques for antivirus and endpoint detection systems. It covers AMSI memory patching, ETW disabling, .NET assembly loading, shellcode execution via callbacks, process injection methods, EDR unhooking with syscalls, and payload encryption to evade signature-based detection.

MITupdated Jun 2026
★ 1,480repo stars
edr-evasion
by hypnguyen1209 · hypnguyen1209/offensive-claude

EDR Evasion covers defensive bypass methods used in red team engagements, from userland hook removal and direct syscall execution to AMSI patching and memory encryption. Learn how EDRs monitor endpoints and the techniques—including PPID spoofing, process injection variants, and ETW patching—that evade their detection.

MITupdated Jul 2026
★ 326repo stars
windows-mitigations-bypass
by hypnguyen1209 · hypnguyen1209/offensive-claude

This skill maps techniques for defeating Windows exploit mitigations—memory protections like ASLR, DEP, CFG, and CET—alongside platform security controls including WDAC, ASR, AMSI, ETW, and PPL. It pairs each bypass method with detection signatures and operational security notes to support both offensive testing and defensive hardening. Includes reconnaissance scripts, gadget finders, and a quick-start workflow for fingerprinting a target's mitigation landscape before weaponizing an exploit.

MITupdated Jul 2026
★ 326repo stars
Windows Kernel Exploits
by blacklanternsecurity · blacklanternsecurity/red-run

This skill guides penetration testers through identifying and exploiting Windows kernel vulnerabilities for privilege escalation. It covers automated vulnerability assessment using tools like WES-NG and Watson, then walks through exploitation of named CVEs including PrintNightmare, EternalBlue, and others, with emphasis on reliability and crash risk mitigation.

GPL-3.0updated Apr 2026
★ 241repo stars
privesc-windows
by hypnguyen1209 · hypnguyen1209/offensive-claude

privesc-windows guides you through multiple privilege-escalation paths on Windows hosts, from token-impersonation attacks (GodPotato, SigmaPotato, PrintNotifyPotato) and UAC bypass techniques to service/DLL hijacking and kernel exploits. It covers enumeration, exploitation, and credential harvesting with tactical OPSEC guidance and detection evasion for each method.

MITupdated Jul 2026
★ 326repo stars
windows-boundaries
by hypnguyen1209 · hypnguyen1209/offensive-claude

Windows Boundaries equips you with techniques and tools to cross Windows security boundaries—from kernel/user mode transitions via win32k/dxgkrnl exploits and BYOVD drivers, to UAC elevation, AppContainer/LPAC sandbox escapes, PPL circumvention, and RPC/ALPC-based token impersonation. Includes enumeration scripts, proof-of-concept exploits, and OPSEC guidance for each attack vector.

MITupdated Jul 2026
★ 326repo stars

More skills Bitdefender Security Analysis (NOASSERTION) · Windows Token Impersonation (GPL-3.0)

Tags
security-evasionthreat-researchdetection-avoidanceoffensive-securityendpoint-hardeningmalware-analysisred-team-toolsvulnerability-assessment