Skip to content
Back to skills

Reverse Eng Edr Analysis

ASecurity

Reverse engineer the EDR/AV on an authorized target host, then evade it — fingerprint the product, dump its userland hook table, and assemble a matching bypass stack: ntdll unhooking, direct/indirect syscalls (Hell's/Halo's/Tartarus Gate), ETW and AMSI patching, hardware-breakpoint Blindside, call-stack spoofing, PPID spoof, sleep masks. Load for "bypass EDR", implant OPSEC against CrowdStrike/Defender/SentinelOne, or when telemetry keeps killing your payload. Signals: unhook, direct syscall,...

  • 20 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added October 4, 2026
ai-agentspythongoshellgitapi

Works with

  • api

Security analysis

A100/100

Pro scans all 2 files and shows the line behind each finding

Scanned October 4, 2026

npx -y skills add NoorQureshi/SploitAgent --skill reverse-eng-edr-analysis --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Reverse Eng Edr Analysis?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Reverse Eng Edr Analysis
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/noorqureshi-reverse-eng-edr-analysis/badge)](https://www.skillsdirectory.com/skills/noorqureshi-reverse-eng-edr-analysis)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: reverse-eng-edr-analysis
description: >
  Reverse engineer the EDR/AV on an authorized target host, then evade it — fingerprint the
  product, dump its userland hook table, and assemble a matching bypass stack: ntdll unhooking,
  direct/indirect syscalls (Hell's/Halo's/Tartarus Gate), ETW and AMSI patching, hardware-breakpoint
  Blindside, call-stack spoofing, PPID spoof, sleep masks. Load for "bypass EDR", implant OPSEC
  against CrowdStrike/Defender/SentinelOne, or when telemetry keeps killing your payload. Signals:
  unhook, direct syscall, ETW patch, AMSI patch, ETW-TI, Sysmon evasion, MITRE T1562. Pentest only.
domain: reverse-engineering
type: methodology
stability: learning
modes: [pentest]
severity: high
mitre: [T1562, T1562.001, T1562.006, T1027, T1055]
tools: [windbg, ida, pe-sieve, syswhispers3, api-monitor, sysmon]
schema_version: 1
---

# EDR analysis & evasion (red team)

## When it applies
An authorized red-team / adversary-emulation engagement requires an implant to survive on a host
running a modern EDR, or you're evaluating an EDR's detection coverage against your own
environment. Confirm the engagement covers defense evasion in writing first (`tradecraft-scope-roe`
+ `scope.txt`) — this is pentest-only, never bug bounty. You need the EDR's internals understood
(`reverse-eng-binary-triage` on its DLLs) before you can evade them deliberately.

## Why it works
An EDR is not a black box: it watches four surfaces — userland `ntdll` inline hooks, kernel
callbacks (Ps/Cm/Ob routines), ETW telemetry (notably the Threat-Intelligence provider), and AMSI
scans — and every one of them can be reverse engineered with IDA/windbg and then neutralized with a
matching technique. No single bypass is enough (unhooking doesn't stop ETW; an AMSI patch doesn't
stop syscall hooks), and the order matters: blind the telemetry before you touch memory the
telemetry watches.

## Method
> **Hook survey, unhook/syscall techniques, ETW/AMSI patch bytes, and the OPSEC order:** see
> [`cheatsheet.md`](cheatsheet.md) next to this file.

1. **Fingerprint the EDR on the host** — services, drivers, minifilters:
   `Get-Service | Where-Object {$_.Name -match 'CSAgent|SentinelAgent|elastic-endpoint|ekrn|MsMpEng|sysmon'}`,
   `fltmc filters`. Match against the fingerprint table in the cheatsheet to learn which surfaces
   this product actually uses.
2. **Dump its hook table.** Attach windbg to any injected process, dump the in-memory `ntdll.dll`
   `.text`, and diff it against the clean on-disk `C:\Windows\System32\ntdll.dll` — every divergence
   is a hook. Faster: `pe-sieve64.exe /pid <pid> /shellc 3 /modules 3 /dir hooks_dump`. Follow the
   `jmp` targets to identify the EDR module behind each trampoline.
3. **Pick the bypass combo per surface:**
   - ntdll inline hooks → indirect syscalls with dynamic SSN resolution (Halo's Gate; SysWhispers3
     `--mode jumper`), or HWBP Blindside (no memory writes at all)
   - ETW-TI → patch `EtwEventWrite` head (`xor eax,eax; ret`) — after securing an unhooked
     `NtProtectVirtualMemory` path
   - AMSI (PowerShell/.NET) → patch `AmsiScanBuffer` (`mov eax,0x80070057; ret`) or HWBP variant
   - kernel callbacks → you can't unhook from userland: call-stack spoof and use legitimate trigger
     chains
   - Sysmon ProcessCreate → PPID spoof to `explorer.exe`, avoid remote threads (Event ID 8) and
     hollowing (Event ID 25)
4. **Implement in the implant.** Generate syscall stubs with SysWhispers3
   (`python3 syswhispers.py --preset all --action edit --mode jumper -o syscalls`), add an
   ETW/AMSI patch step, and wrap execution in a call-stack spoofer. For long residency, add a sleep
   mask (Ekko/Foliage) that encrypts the implant's `.text` and zeroes the stack while sleeping.
5. **Validate in a local sandbox copy** of the target stack (trial EDR; Defender + Sysmon with the
   olaf config is a good baseline: `sysmon64.exe -i sysmonconfig.xml`). Run the implant and watch
   Defender AMSI, ETW-TI, Sysmon Event IDs 1/7/8/10/25, and the EDR console — silence on all four
   is the bar.
6. **Deliver quietly** — drop into legitimate software directories, PPID-spoof the launcher, then
   continue the kill chain (lateral movement, persistence) per the engagement plan.

## Gotchas
- **Order is everything** — AMSI → ETW → (indirect-syscall `NtProtectVirtualMemory`) → unhook →
  stack spoof → payload. Unhook first and ETW-TI reports the memory modification before you're
  blind.
- **Direct syscalls are visible from kernel** — a `syscall` instruction executing from your
  implant's `.text` instead of ntdll is itself a signal; use *indirect* syscalls (`jmp` into a
  legitimate ntdll `syscall;ret`).
- **Hell's Gate breaks on hooked ntdll** — the SSN isn't in the first bytes anymore; Halo's Gate
  infers it from unhooked neighbours (SSNs increment sequentially).
- **Spoof during sleep too** — EDRs sample stacks periodically, not just at syscall time.
- **Per-thread hardware breakpoints** — Blindside DRx settings don't propagate; set them on every
  thread, and note `NtSetContextThread` may itself be hooked.
- **Never treat "no alert in one run" as proof** — validate across reboots, sleep cycles, and the
  EDR's cloud lookups.

## Verify success
The implant executes its full action (injection, credential access, C2 callback) on the sandboxed
target stack with zero detections across AMSI, ETW-TI, Sysmon, and the EDR console — reproducibly,
including after a sleep cycle. Report against ATT&CK T1562.001/.006, T1027, T1055.

## References
pe-sieve; SysWhispers3; Hell's/Halo's/Tartarus Gate PoCs; CallStackSpoofer & SilentMoonwalk; Ekko/
Foliage sleep masks; MITRE ATT&CK T1562. Find the EDR's DLLs worth reversing with
`reverse-eng-binary-triage`; the defender's view is `defense-detection-sigma`.

---
_Portions adapted from [reverse-skill](https://github.com/zhaoxuya520/reverse-skill) by zhaoxuya520, MIT License._

Files in this skill

  • SKILL.md5.8 KB
  • cheatsheet.md8 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…