defense-evasion - Endpoint defense evasion techniques
Explains AMSI and ETW patching, ScareCrow payload generation, custom loaders, syscalls, LOLBAS execution, and process injection.
Tags
Updated: 2026-10-06Capabilities
Typical Inputs
Typical Outputs
What this skill does
- Patch AMSI memory
- Patch ETW functions
- Generate ScareCrow payloads
- Build custom shellcode loaders
- Use direct syscalls
- Execute through LOLBAS
- Inject into processes
Inputs
- Shellcode binary
- Encryption key
- Target domain
- Injection process path
- Loader source code
Outputs
- Evasive payload binaries
- DLL loader files
- Custom loader source code
- Modified process AMSI state
- Modified process ETW state
Requirements
- Bash access
- Read access
- Write access
- Windows environment
