edr-evasion-dev
Installation
SKILL.md
EDR Evasion — Universal Patterns & Constraints
Field-tested principles for Windows and Linux EDR/XDR evasion. Windows content verified against S1, Defender, CrowdStrike (2026). Linux content covers Falco, Tetragon, Tracee, Aqua, Elastic Defend, CrowdStrike Falcon Linux, SentinelOne Linux (2024-2026). Project-agnostic — applies to any loader, implant, or tool runner.
Cross-Platform Routing
Depth in this SKILL.md is Windows. Load references based on the target OS.
| Target profile | Load |
|---|---|
| Windows 10/11 loader, implant, tool | This body §0–§14 + references/constraints.md |
| Windows 11 24H2+ with CET on ntdll | Same + references/kernel-telemetry.md — read §CET before choosing spoof strategy |
| Linux host with Falco / Tetragon / Tracee / Elastic Defend / any eBPF EDR | references/linux-edr-evasion.md — do not port Windows patterns |
| Designing a new loader / auditing an existing one (either OS) | references/best-practices.md — signal-cost budget, minimalism gate, CI-under-test |
| Deciding what you can never suppress from userspace | references/kernel-telemetry.md — kernel-fired ETW-TI, LSM BPF, auditd |
Golden rule for cross-OS work: usermode evasion primitives never transfer. Indirect syscalls, ETW patching, SilentMoonwalk, HWBP are Windows-only. LD_PRELOAD, io_uring, memfd, BPF map poisoning are Linux-only. What transfers is the doctrine: evasion minimalism, signal-cost budget, staged loader hygiene, telemetry-first design (see best-practices.md).