A comprehensive collection of practical demonstrations showcasing fundamental evasion techniques against antivirus and EDR solutions. Features examples using C++, C#, Syscalls, and APC injection.
-
Updated
Jul 12, 2026
A comprehensive collection of practical demonstrations showcasing fundamental evasion techniques against antivirus and EDR solutions. Features examples using C++, C#, Syscalls, and APC injection.
Advanced payload creation framework for bypassing EDR solutions and Application Whitelisting using DLL side-loading, in-memory unhooking, and indirect syscalls.
A C++ security research framework demonstrating Windows UAC bypass techniques (AMSI/ETW patching, Registry hijacking) paired with a high-speed, real-time memory and registry sentinel designed to detect and mitigate privilege escalation attempts.
Add a description, image, and links to the etw-patching topic page so that developers can more easily learn about it.
To associate your repository with the etw-patching topic, visit your repo's landing page and select "manage topics."