edr-bypass-re
Warn
Audited by Gen Agent Trust Hub on Jul 4, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill's bootstrap process (
bootstrap-reverse.ps1) is designed to automatically download and install tools from external sources, including GitHub repositories forpe-sieve,syswhispers3, and various implementations of 'Gate' techniques (Hell's, Halo's, and Tartarus Gate). - [REMOTE_CODE_EXECUTION]: The skill provides instructions for downloading and executing third-party tools and scripts to modify system behavior, such as
pe-sieve64.exefor hook detection andsyswhispers.pyfor syscall stub generation. - [COMMAND_EXECUTION]: The skill contains numerous shell commands for system reconnaissance and anti-forensics, including EDR fingerprinting via
Get-Serviceandfltmc, clearing PowerShell history, and stopping system logging services usinglogman. - [PROMPT_INJECTION]: The skill provides detailed code snippets and techniques specifically designed to override or bypass system-level security filters like AMSI (Antimalware Scan Interface) and ETW (Event Tracing for Windows), which are fundamental safety mechanisms in the Windows environment.
Audit Metadata