asm-offensive-patterns
Installation
SKILL.md
Offensive Assembly Patterns
Full spectrum of low-level assembly techniques for offensive security:
shellcode, loaders, BOFs, evasion primitives, and stealth infrastructure.
Apply to all .asm, .s, .S files that touch evasion, injection, hooking, or stealth execution.
Scope: Authorized red team / research use only.
1. Syscall Strategies
1.1 Direct Syscall
Issue SYSCALL directly from own .text — bypasses all userland hooks.
Detection risk: kernel-side ETW sees RIP outside ntdll -> high signal for modern EDRs.
Use before ntdll hooks load (Early-Bird), or where kernel callbacks are not deployed.