edr-evasion

Fail

Audited by Gen Agent Trust Hub on May 26, 2026

Risk Level: HIGHCOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides C code for "Userland Unhooking" which involves manually overwriting the .text section of the system library ntdll.dll in memory to remove monitoring hooks placed by security software.
  • [COMMAND_EXECUTION]: Includes memory patching code for the Antimalware Scan Interface (amsi.dll) and Event Tracing for Windows (EtwEventWrite). These techniques are specifically designed to blind security products and suppress logging of malicious activities.
  • [COMMAND_EXECUTION]: Contains implementation details for sophisticated process injection techniques such as ThreadlessInject and Early Bird. These methods allow an attacker to execute arbitrary code inside legitimate processes to evade detection.
  • [COMMAND_EXECUTION]: Provides code for "PPID Spoofing", which manipulates the parent process attribute of a new process to make it appear as though it was launched by a trusted system component like explorer.exe.
  • [COMMAND_EXECUTION]: Describes sandbox and virtual machine detection logic (checking hardware resources and user interaction) used to hide malicious behavior when running in analysis environments.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
May 26, 2026, 08:57 AM
Security Audit — agent-trust-hub — edr-evasion