windows-av-evasion
Audited by Socket on Apr 9, 2026
2 alerts found:
Malwarex2MALICIOUS. The skill is an explicit offensive playbook for evading Windows security controls and executing payloads stealthily. Its capabilities are inherently incompatible with benign agent assistance, and the linked offensive tools plus transitive skill loading further increase operational risk.
This fragment is a direct, highly actionable AMSI/EDR bypass and payload-execution playbook. It provides multiple complementary evasion techniques (memory patching of AmsiScanBuffer, reflection-based AMSI state manipulation, COM/registry hijacking, and hardware-breakpoint return-value tampering) and shows how to chain those bypasses to in-memory execution of attacker-controlled code (including remote download/decrypt workflows). Treat as a severe compromise indicator and an unsafe supply-chain risk.