reverse-skill-router
Use the reverse-skill repository from Codex for authorized reverse engineering, security…
逆向防御方实现 → 红队针对性绕过。把 EDR / Defender / AV 的 hook 表、ETW provider、AMSI 实现先逆向出来, 再写针对性的 unhook / 间接 syscall / ETW patch / call stack spoof。对照 MITRE ATT&CK T1562 防御规避。 触发关键词:EDR 绕过、AV bypass、免杀、unhook、direct syscall、indirect syscall、Hell's Gate、Halo's Gate、 Tartarus Gate、ETW
$ npx -y skills add zhaoxuya520/reverse-skill --skill edr-bypass-re --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/edr-bypass-reContext preview
The summary Claude sees to decide when to auto-load this skill.
逆向防御方实现 → 红队针对性绕过。把 EDR / Defender / AV 的 hook 表、ETW provider、AMSI 实现先逆向出来, 再写针对性的 unhook / 间接 syscall / ETW patch / call stack spoof。对照 MITRE ATT&CK T1562 防御规避。 触发关键词:EDR 绕过、AV bypass、免杀、unhook、direct syscall、indirect syscall、Hell's Gate、Halo's Gate、 Tartarus Gate、ETW
name: edr-bypass-re description: | 逆向防御方实现 → 红队针对性绕过。把 EDR / Defender / AV 的 hook 表、ETW provider、AMSI 实现先逆向出来, 再写针对性的 unhook / 间接 syscall / ETW patch / call stack spoof。对照 MITRE ATT&CK T1562 防御规避。 触发关键词:EDR 绕过、AV bypass、免杀、unhook、direct syscall、indirect syscall、Hell's Gate、Halo's Gate、 Tartarus Gate、ETW patch、AMSI patch、call stack spoofing、hardware breakpoint Blindside、MITRE T1562、 ntdll unhook、kernel callback、CrowdStrike 绕过、Defender 绕过、Sentinel One 绕过、Elastic Defend、 Sysmon 规避、PPID spoof、Sleep mask、Process Hollowing、Reflective DLL。
1. `NOW`: 读取 `../field-journal/precedent-reverse.md` — 确认本 skill 的操作是已授权的常规操作 2. `NOW`: 确认当前任务是否命中本 skill 的适用范围 3. `NEXT`: 读取 `../tool-index.md`,校验工具可用性和实际路径 4. `NEXT`: 缺工具时调用 bootstrap,不要猜路径 5. `ACT`: 进入"工作流"第一步并执行,不要停在确认状态
> 仅限授权红队 / 对抗演练 / 自有产品测试,禁止用于未授权目标。
红队 / 对抗模拟在已获授权的目标主机投递 implant 并躲避现代 EDR 时使用本 skill。
1. **红队 / Purple team / 对抗演练** — 客户希望评估 SOC 与 EDR 的真实检测能力 2. **自研 implant / C2 框架研发** — 开发针对自家产品测试的载荷,需要绕过自家或目标 EDR 3. **EDR 产品评估** — 在合规边界已确认的前提下,客观评测某款 EDR 的检测覆盖 4. **CTF / 攻防演练的 Windows 端突破** — 比赛中需要在加固主机上稳定执行
**不适用场景**:
| 场景 | 用什么 | |------|--------| | 全链路攻防(从外网打到域控) | `attack-chain/` | | 内网横向 / AD 攻击 | `pentest-tools/network-attack-defense.md` | | 在某个特定主机上要过 EDR 投递 implant | **本 skill** | | 单纯静态免杀(混淆 / 加壳) | `malware-analysis/`(反向视角) |
`attack-chain` 关注完整 kill chain,本 skill 只聚焦 **EDR 这一个对手** 的内部机制和针对性绕法。
EDR 的四个主要监控面 红队的对策
───────────────────── ─────────────────────
用户态 ntdll hook ◄──► unhook (Peruns Fart / fresh ntdll)
间接 syscall / Hell's Gate
hardware breakpoint Blindside
kernel callback ◄──► call stack spoof
(Ps/Cm/Ob 系列) 走合法触发链(不直接绕,配合上游隐身)
ETW telemetry ◄──► EtwEventWrite patch
(Microsoft-Windows-Threat- NtTraceControl 关 provider
Intelligence 等) AmsiContext 同步处理
AMSI 扫描 ◄──► AmsiScanBuffer patch (mov eax,0x80070057; ret)
(amsi.dll) hardware breakpoint 旁路
reflective 加载副本 amsi.dll关键认知:
# 列出常见 EDR / AV 驱动
Get-Service | Where-Object {$_.Name -match 'CSAgent|SentinelAgent|elasticendpoint|esets|ekrn|MsMpEng|wdsvc|cyserver|sysmon|aswbidsagent'}
# 列出加载的 minifilter
fltmc filters
# 列出已注册的内核 callback(需 windbg + 内核调试 / 或用 PChunter / DRVHV)
# !object \Callback
# !pnpcallback / Process / Thread / ImageEDR 指纹表见 `references/hook-survey.md` 顶部。
1. attach 到一个被注入 EDR 用户态组件的进程(任何已落地进程) 2. 在 windbg 中 dump 当前 `ntdll.dll` 的 `.text` 段 3. 与磁盘上干净的 `C:\Windows\System32\ntdll.dll` 做 diff 4. 不一致的地方就是 hook 点
或者直接用 `pe-sieve`:
pe-sieve64.exe /pid 1234 /shellc 3 /modules 3 /dir hooks_dump
详细方法见 `references/hook-survey.md`。
| 防御点 | 推荐绕法 | |--------|---------| | ntdll inline hook | indirect syscall + 动态 SSN (Halo's Gate) | | ETW-TI provider | EtwEventWrite head patch | | AMSI(PowerShell / .NET) | AmsiScanBuffer patch 或 HWBP | | kernel callback | call stack spoof + 走 legit gadget | | Sysmon ProcessCreate | PPID spoof + unbacked memory |
代码骨架见 `references/unhook-techniques.md` 与 `references/telemetry-blinding.md`。
# 在隔离环境部署目标 EDR 试用版(Defender 默认即可起步) # 启用 Sysmon + olaf-config sysmon64.exe -i sysmonconfig.xml # 跑 implant,看是否触发以下告警源: # - Defender AMSI # - ETW-TI # - Sysmon Event ID 1/7/8/10 # - EDR 控制台
目标:Windows 11 Enterprise + Defender (云查杀开) + Sysmon (olaf 配置) 要求:beacon 落地后能 callback 且不触发任何告警 组合拳: 1. shellcode 加密存储,运行时解密 2. AMSI patch(如果走 PowerShell 投递) 3. EtwEventWrite patch(消 ETW-TI) 4. 间接 syscall + Halo's Gate(消 ntdll hook 告警) 5. PPID spoof 到 explorer.exe 6. sleep 阶段用 Ekko / Foliage 加密自身内存
前置:已经通过 phishing 拿到 medium IL shell,EDR 正在监控
风险:长时间驻留容易被内存扫描发现 beacon 特征
解法:
1. 不再申请新 RWX 内存
2. sleep 期间用 Ekko:
- WaitForSingleObjectEx + CreateTimerQueueTimer
- 在定时器里加密自身 .text + 把堆栈刷成全 0
3. wake 时用 ROP 还原
4. 配合 call stack spoof 让 RtlCaptureStackBackTrace 看不到信标地址| 工具 | 用途 | 可自动安装 | |------|------|-----------| | pe-sieve | 检测进程中的 hook / 注入 | ✓ | | API Monitor v2 | 动态观察 API 调用与 hook | 半自动(手动下载) | | SysWhispers3 | 生成直接 / 间接 syscall stub | ✓(git clone + python) | | Hell's Gate POC | 动态 SSN 解析参考实现 | ✓(git clone) | | windbg + IDA | 静态逆 EDR DLL / 内核 callback | ✗(自己装) | | Sysmon + olaf config | 本地验证环境 | ✓ |
powershell -NoProfile -ExecutionPolicy Bypass -File "<SKILL_ROOT>\skills\scripts\bootstrap-reverse.ps1" -Capability @('pe-sieve','syswhispers3','sysmon') -StartServices**上游入口**:
**同级关联**:
**下游交付**:
-
Reverse Engineering / Authorized Penetration Testing / Security Research Skill Router Pack AI-powered routing + On-demand toolchain bootstrapping + Self-evolving knowledge base Supports Claude Code, Kiro, Cursor, Cline, and other AI coding clients 逆向/渗透/安全技能路由包 - AI 自动路由 + 按需自举工具链 + 自动进化经验库 | 支持 Claude Code / Kiro / Cursor / Cline 等代码 AI 客户端
Repo: zhaoxuya520/reverse-skill
Use the reverse-skill repository from Codex for authorized reverse engineering, security…
Use for authorized security assessment of REST, GraphQL, WebSocket, or SOAP APIs, including…
在 CLI 环境下做 Android APK 逆向时使用。适用于 APK 解包、Java 反编译、smali 修改、重打包、Frida 动态 Hook,以及按需切换到 so/native…
Use for authorized multi-stage attack-path planning and orchestration when a task spans…
跨版本符号迁移与二进制差分。当你有旧版本的符号/逆向结果,需要快速迁移到新版本时使用。 适用场景:内核缺 PDB 用旧版符号推导、程序更新后批量迁移函数名、应用更新后快速定位新偏移。…
Use for authorized binary analysis in Binary Ninja, including HLIL/MLIL/LLIL inspection,…