edr-evasion-dev

Installation
SKILL.md

EDR Evasion — Universal Patterns & Constraints

Field-tested principles for Windows and Linux EDR/XDR evasion. Windows content verified against S1, Defender, CrowdStrike (2026). Linux content covers Falco, Tetragon, Tracee, Aqua, Elastic Defend, CrowdStrike Falcon Linux, SentinelOne Linux (2024-2026). Project-agnostic — applies to any loader, implant, or tool runner.


Cross-Platform Routing

Depth in this SKILL.md is Windows. Load references based on the target OS.

Target profile Load
Windows 10/11 loader, implant, tool This body §0–§14 + references/constraints.md
Windows 11 24H2+ with CET on ntdll Same + references/kernel-telemetry.md — read §CET before choosing spoof strategy
Linux host with Falco / Tetragon / Tracee / Elastic Defend / any eBPF EDR references/linux-edr-evasion.md — do not port Windows patterns
Designing a new loader / auditing an existing one (either OS) references/best-practices.md — signal-cost budget, minimalism gate, CI-under-test
Deciding what you can never suppress from userspace references/kernel-telemetry.md — kernel-fired ETW-TI, LSM BPF, auditd

Golden rule for cross-OS work: usermode evasion primitives never transfer. Indirect syscalls, ETW patching, SilentMoonwalk, HWBP are Windows-only. LD_PRELOAD, io_uring, memfd, BPF map poisoning are Linux-only. What transfers is the doctrine: evasion minimalism, signal-cost budget, staged loader hygiene, telemetry-first design (see best-practices.md).

Installs
5
GitHub Stars
22
First Seen
Aug 23, 2026
edr-evasion-dev — aeondave/malskill