asm-offensive-patterns

Installation
SKILL.md

Offensive Assembly Patterns

Full spectrum of low-level assembly techniques for offensive security: shellcode, loaders, BOFs, evasion primitives, and stealth infrastructure. Apply to all .asm, .s, .S files that touch evasion, injection, hooking, or stealth execution.

Scope: Authorized red team / research use only.


1. Syscall Strategies

1.1 Direct Syscall

Issue SYSCALL directly from own .text — bypasses all userland hooks. Detection risk: kernel-side ETW sees RIP outside ntdll -> high signal for modern EDRs. Use before ntdll hooks load (Early-Bird), or where kernel callbacks are not deployed.

Installs
8
GitHub Stars
22
First Seen
Apr 16, 2026
asm-offensive-patterns — aeondave/malskill