AV/EDR evasion playbook for Windows. Use when bypassing AMSI, ETW, .NET assembly detection, shellcode execution, process injection, API hooking, and signature-based detection on Windows endpoints.
Detected risks:
An offensive-security playbook in the yaklang hack-skills collection, focused on antivirus and EDR evasion on Windows endpoints for authorized red-team and adversary-simulation engagements. Per its own description it addresses bypassing defensive mechanisms such as AMSI (the Antimalware Scan Interface), ETW (Event Tracing for Windows), .NET assembly detection, and signature-based detection, along with related topics like shellcode execution, process injection, and API hooking. It is framed as an expert-level playbook that assumes solid knowledge of Windows internals and modern endpoint defenses. In a catalog context it is best understood as advanced red-team tooling used to measure how effectively a Windows environment's defensive stack detects and prevents contemporary evasion, and to validate detection-engineering work. Because it centers on detection-evasion, it carries significant misuse potential and should be used only within the scope of an authorized security assessment with explicit permission. Blue teams can use awareness of these categories to prioritize AMSI/ETW telemetry, harden EDR configuration, and build detections for the behaviors the playbook targets.
It is an offensive-security playbook covering antivirus/EDR evasion concepts on Windows, used in authorized red-team assessments to test how well endpoint defenses detect modern evasion.
Per its description: AMSI, ETW, .NET assembly detection, shellcode execution, process injection, API hooking, and signature-based detection on Windows endpoints.
Experienced red-team operators and penetration testers working under explicit authorization; it assumes familiarity with Windows internals and endpoint security.
No. Detection-evasion techniques carry significant misuse potential and must only be used within an authorized engagement with permission.
Blue teams can prioritize AMSI/ETW telemetry, harden EDR, and build detections for the evasion categories the playbook targets.
Quick Setup:
.claude/skills/Repository
yaklang/hack-skills