edr-bypass-re

Fail

Audited by Socket on Jul 4, 2026

4 alerts found:

Securityx2Malwarex2
SecurityMEDIUM
SKILL.md
SecurityMEDIUM
references/hook-survey.md
MalwareHIGH
references/telemetry-blinding.md

This fragment provides highly actionable instructions to disable or bypass Windows security telemetry (ETW) and anti-malware scanning (AMSI), then reduce forensic visibility by turning off PowerShell logging and deleting/clearing event tracing and evidence (Security.evtx/ETL, Prefetch, history) while spoofing file timestamps. The combination of concrete function-patching byte patterns, telemetry suppression, and anti-forensics workflow strongly matches malicious intrusion/evasion tradecraft. It should be treated as an extreme security risk for any software supply chain.

Confidence: 90%Severity: 100%
MalwareHIGH
references/unhook-techniques.md

High-confidence negative security finding. This fragment is an offensive, highly actionable Windows EDR/telemetry-evasion tradecraft guide describing techniques used to bypass user-mode hooks and manipulate kernel-transition and forensic visibility (unhook/remap ntdll, direct/indirect syscall stubs/gadgets, VEH RIP rewriting with hardware breakpoints, and call stack spoofing). Even though presented as “authorized” guidance and not as runnable code here, its content would materially enable misuse if packaged or distributed in a software supply chain.

Confidence: 86%Severity: 100%
Audit Metadata
Analyzed At
Jul 4, 2026, 02:01 AM
Package URL
pkg:socket/skills-sh/zhaoxuya520%2Freverse-skill%2Fedr-bypass-re%2F@406ceef35cfe71ec831063e132f5dca1922f0187b694201adfa3e29496cbf85c
Security Audit — socket — edr-bypass-re