edr-bypass-re

Warn

Audited by Gen Agent Trust Hub on Jul 4, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill's bootstrap process (bootstrap-reverse.ps1) is designed to automatically download and install tools from external sources, including GitHub repositories for pe-sieve, syswhispers3, and various implementations of 'Gate' techniques (Hell's, Halo's, and Tartarus Gate).
  • [REMOTE_CODE_EXECUTION]: The skill provides instructions for downloading and executing third-party tools and scripts to modify system behavior, such as pe-sieve64.exe for hook detection and syswhispers.py for syscall stub generation.
  • [COMMAND_EXECUTION]: The skill contains numerous shell commands for system reconnaissance and anti-forensics, including EDR fingerprinting via Get-Service and fltmc, clearing PowerShell history, and stopping system logging services using logman.
  • [PROMPT_INJECTION]: The skill provides detailed code snippets and techniques specifically designed to override or bypass system-level security filters like AMSI (Antimalware Scan Interface) and ETW (Event Tracing for Windows), which are fundamental safety mechanisms in the Windows environment.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 4, 2026, 02:01 AM
Security Audit — agent-trust-hub — edr-bypass-re