Edr Bypass Re

zhaoxuya520/reverse-skill/skills/edr-bypass-re

作者 zhaoxuya520cab634bd855f無授權條款40K 個星標收錄於 2026年10月9日更新於 2026年10月9日儲存庫2 週前更新

逆向防御方实现 → 红队针对性绕过。把 EDR / Defender / AV 的 hook 表、ETW provider、AMSI 实现先逆向出来, 再写针对性的 unhook / 间接 syscall / ETW patch / call stack spoof。对照 MITRE ATT&CK T1562 防御规避。 触发关键词:EDR 绕过、AV bypass、免杀、unhook、direct syscall、indirect syscall、Hell's Gate、Halo's Gate、 Tartarus Gate、ETW patch、AMSI patch、call stack spoofing、hardware breakpoint Blindside、MITRE T1562、 ntdll unhook、kernel callback、CrowdStrike 绕过、Defender 绕过、Sentinel One 绕过、Elastic Defend、 Sysmon 规避、PPID spoof、Sleep mask、Process Hollowing、Reflective DLL。

僅含說明Security

僅公開檔案列表。將技能安裝到工作區後即可檢視檔案內容。

路徑大小類型
references/hook-survey.md9.4 KBtext/markdown
references/telemetry-blinding.md12.4 KBtext/markdown
references/unhook-techniques.md10.8 KBtext/markdown
SKILL.md9.2 KBtext/markdown

來源與署名

來源:zhaoxuya520/reverse-skill位於skills/edr-bypass-re提交cab634b

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架