← All cheat sheets

EDR-EVASION

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

OVERVIEW#

Endpoint Detection & Response (EDR) products observe process, memory,
API, and telemetry signals. This sheet is a conceptual reference of
the evasion CATEGORIES red teams test and blue teams must detect -
AMSI/ETW telemetry, user-land hooking, and Defender operations. It is
oriented to detection engineering and authorized assessment, not a
weaponization walkthrough.

TELEMETRY SOURCES EDR USES#

# Understand what you must defeat OR must not lose visibility of:
# - ETW (Event Tracing for Windows) providers
# - AMSI (Antimalware Scan Interface) - script/.NET content scanning
# - Kernel callbacks (process/thread/image/registry notify routines)
# - User-mode API hooks (ntdll/kernel32 inline hooks)
# - Minifilter drivers (file I/O), WFP (network)
# - Sysmon (if deployed) as complementary telemetry

AMSI (SCRIPT/.NET SCANNING)#

# AMSI scans PowerShell, VBScript, JScript, and in-memory .NET
# Evasion CATEGORIES tested by red teams:
#   - obfuscation / string splitting to avoid signatures
#   - patching amsi.dll AmsiScanBuffer in the local process
#   - loading logic in a context AMSI does not instrument
# DETECTION: AMSI_RESULT events, PowerShell 4104 script-block logging,
#   Defender AMSI telemetry, unusual amsi.dll writes/patches

ETW TAMPERING#

# ETW carries much EDR .NET/PowerShell telemetry
# Categories: patching/blinding ETW providers in-process, disabling
#   the CLR ETW provider, provider unregistration
# DETECTION: gaps in expected ETW streams, EtwEventWrite patches,
#   process self-modifying ntdll ETW stubs (memory-integrity signals)

USER-LAND UNHOOKING#

# Many EDRs place inline hooks in ntdll.dll user-mode stubs
# Categories: reloading a clean ntdll from disk/KnownDLLs, direct or
#   indirect syscalls to bypass hooked stubs, hook detection
# DETECTION: private/unbacked executable memory (RX in non-image
#   regions), syscall instructions from non-ntdll modules, image-load
#   of a second ntdll copy

PROCESS INJECTION FAMILIES (TELEMETRY VIEW)#

# Not code - the classes EDR watches for:
#   - remote thread creation (CreateRemoteThread)
#   - APC injection, thread hijacking
#   - section mapping / process hollowing
#   - callback/PoolParty style abuse
# DETECTION: cross-process memory writes, RWX allocations, thread
#   start addr in unbacked memory, VirtualProtect to executable

DEFENDER OPERATIONS (NATIVE)#

# Legitimate admin/audit commands:
Get-MpComputerStatus                 # Defender health/state
Get-MpPreference                     # Current settings
Get-MpThreatDetection                # Detection history
Set-MpPreference -DisableRealtimeMonitoring $true  # (admin; audited)
Add-MpPreference -ExclusionPath C:\x # Exclusion (abuse = red flag)
Get-MpPreference | Select Exclusion* # AUDIT: review exclusions
# Tampering with these (esp. adding exclusions) is a key detection

DETECTION-ENGINEERING ANGLE#

# For each evasion class, ensure you have a detection:
#   AMSI patch      -> AMSI/Defender tamper alerts + 4104
#   ETW blinding    -> stream-gap analytics, memory integrity
#   Unhooking       -> unbacked-memory + syscall-origin analytics
#   Injection       -> cross-proc write + RWX + remote thread
#   Defender tamper -> MpPreference exclusion/RTP-disable events
# Validate with Atomic Red Team / purple-team runs

EXAMPLES#

# Audit Defender exclusions across a fleet (blue team)
Get-MpPreference | Select-Object -ExpandProperty ExclusionPath

# Confirm real-time protection and tamper protection are on
Get-MpComputerStatus | Select RealTimeProtectionEnabled,IsTamperProtected

# Purple-team validation of AMSI/injection detections
# (run known-benign Atomic Red Team tests, verify alerts fire)

NOTES#

- This sheet intentionally stays at the category/telemetry level -
  the goal is detection coverage, not shipping an evasive loader
- Tamper Protection (Defender) blocks most Set/Add-MpPreference abuse;
  verify it is enabled on FS endpoints
- The strongest defensive posture: kernel telemetry (callbacks) +
  Sysmon + AMSI + PowerShell logging, correlated in the SIEM
- Track EDR "blind spots" as findings mapped to DORA ICT risk and
  NIS2 detection-capability requirements
- Pair with LOLBAS.txt, DETECTION-ENGINEERING.txt, DEFENDER-KQL.txt