offensive-edr-evasion
EDR evasion offensive checklist: hook unhooking (user/kernel), direct syscalls, PPID spoofing, process injection variants, AMSI bypass, ETW patching, memory encryption, and behavior-based evasion. Use when planning EDR bypass during red team engagements or researching AV/EDR evasion techniques.
- Compatibility
- claude-code codex opencode
Pinned to revision 626b01ddea63, so it is the text this page describes rather than whatever the author pushed since.
Files
- skills/offensive-edr-evasion/SKILL.md
- skills/offensive-edr-evasion/LICENSE
- skills/offensive-edr-evasion/README.md
- skills/offensive-edr-evasion/agents/openai.yaml
Every link opens the file at its source, pinned to the revision this page describes.