LogoAwesome Skills
  • Search
  • Category
  • Tag
  • Blog
LogoAwesome Skills
LogoAwesome Skills

Discover Open-Source Agent Skills for AI Coding Assistants

Product

  • Search
  • Category
  • Tag
  • Blog

Resources

  • Claude Skill Docs
  • Antigravity Skills Docs

Tools

  • Claude Code
  • OpenCode
  • Cursor
  • Codex
  • Antigravity

Company

  • Privacy Policy
  • Terms of Service
  • Sitemap

©2026 Awesome Skills. All rights reserved.

Privacy PolicyTerms
Back to Skills

windows-av-evasion

AV/EDR evasion playbook for Windows. Use when bypassing AMSI, ETW, .NET assembly detection, shellcode execution, process injection, API hooking, and signature-based detection on Windows endpoints.

1,311stars179forksUpdated 7/8/2026
Security#security#penetration-testing#red-team#av-evasion#windows

Security Assessment

Critical Risk(5/100)

Detected risks:

Agent-reviewed override(Offensive AV/EDR detection-evasion playbook (AMSI/ETW bypass, shellcode execution, process injection). Local assessor's regex didn't match its terminology so it defaulted safe; flagged manually from the doc's own description. Genuine offensive tooling, per gotcha #7.)
Security Score5/100

About windows-av-evasion

An offensive-security playbook in the yaklang hack-skills collection, focused on antivirus and EDR evasion on Windows endpoints for authorized red-team and adversary-simulation engagements. Per its own description it addresses bypassing defensive mechanisms such as AMSI (the Antimalware Scan Interface), ETW (Event Tracing for Windows), .NET assembly detection, and signature-based detection, along with related topics like shellcode execution, process injection, and API hooking. It is framed as an expert-level playbook that assumes solid knowledge of Windows internals and modern endpoint defenses. In a catalog context it is best understood as advanced red-team tooling used to measure how effectively a Windows environment's defensive stack detects and prevents contemporary evasion, and to validate detection-engineering work. Because it centers on detection-evasion, it carries significant misuse potential and should be used only within the scope of an authorized security assessment with explicit permission. Blue teams can use awareness of these categories to prioritize AMSI/ETW telemetry, harden EDR configuration, and build detections for the behaviors the playbook targets.

FAQ

What is this skill for?

It is an offensive-security playbook covering antivirus/EDR evasion concepts on Windows, used in authorized red-team assessments to test how well endpoint defenses detect modern evasion.

What areas does it cover?

Per its description: AMSI, ETW, .NET assembly detection, shellcode execution, process injection, API hooking, and signature-based detection on Windows endpoints.

Who is the intended audience?

Experienced red-team operators and penetration testers working under explicit authorization; it assumes familiarity with Windows internals and endpoint security.

Is it appropriate for unauthorized use?

No. Detection-evasion techniques carry significant misuse potential and must only be used within an authorized engagement with permission.

How can defenders benefit?

Blue teams can prioritize AMSI/ETW telemetry, harden EDR, and build detections for the evasion categories the playbook targets.

All Files

2 files
SKILL.md11.2 KB
View
AMSI_BYPASS_TECHNIQUES.md8.4 KB
View

Install windows-av-evasion

Download and extract the skill files to your .claude/skills/ directory.

Quick Setup:

  1. Copy the skill folder to .claude/skills/
  2. Claude will automatically detect and use the skill

Repository

yaklang/hack-skills

Related Skills

ccf-idea-reviewer

2,958

ccf-integrity-auditor

2,958

finance-sentiment

3,382

ccf-humanization

2,958