EDR-EVASION
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
OVERVIEW#
Endpoint Detection & Response (EDR) products observe process, memory, API, and telemetry signals. This sheet is a conceptual reference of the evasion CATEGORIES red teams test and blue teams must detect - AMSI/ETW telemetry, user-land hooking, and Defender operations. It is oriented to detection engineering and authorized assessment, not a weaponization walkthrough.
TELEMETRY SOURCES EDR USES#
# Understand what you must defeat OR must not lose visibility of: # - ETW (Event Tracing for Windows) providers # - AMSI (Antimalware Scan Interface) - script/.NET content scanning # - Kernel callbacks (process/thread/image/registry notify routines) # - User-mode API hooks (ntdll/kernel32 inline hooks) # - Minifilter drivers (file I/O), WFP (network) # - Sysmon (if deployed) as complementary telemetry
AMSI (SCRIPT/.NET SCANNING)#
# AMSI scans PowerShell, VBScript, JScript, and in-memory .NET # Evasion CATEGORIES tested by red teams: # - obfuscation / string splitting to avoid signatures # - patching amsi.dll AmsiScanBuffer in the local process # - loading logic in a context AMSI does not instrument # DETECTION: AMSI_RESULT events, PowerShell 4104 script-block logging, # Defender AMSI telemetry, unusual amsi.dll writes/patches
ETW TAMPERING#
# ETW carries much EDR .NET/PowerShell telemetry # Categories: patching/blinding ETW providers in-process, disabling # the CLR ETW provider, provider unregistration # DETECTION: gaps in expected ETW streams, EtwEventWrite patches, # process self-modifying ntdll ETW stubs (memory-integrity signals)
USER-LAND UNHOOKING#
# Many EDRs place inline hooks in ntdll.dll user-mode stubs # Categories: reloading a clean ntdll from disk/KnownDLLs, direct or # indirect syscalls to bypass hooked stubs, hook detection # DETECTION: private/unbacked executable memory (RX in non-image # regions), syscall instructions from non-ntdll modules, image-load # of a second ntdll copy
PROCESS INJECTION FAMILIES (TELEMETRY VIEW)#
# Not code - the classes EDR watches for: # - remote thread creation (CreateRemoteThread) # - APC injection, thread hijacking # - section mapping / process hollowing # - callback/PoolParty style abuse # DETECTION: cross-process memory writes, RWX allocations, thread # start addr in unbacked memory, VirtualProtect to executable
DEFENDER OPERATIONS (NATIVE)#
# Legitimate admin/audit commands: Get-MpComputerStatus # Defender health/state Get-MpPreference # Current settings Get-MpThreatDetection # Detection history Set-MpPreference -DisableRealtimeMonitoring $true # (admin; audited) Add-MpPreference -ExclusionPath C:\x # Exclusion (abuse = red flag) Get-MpPreference | Select Exclusion* # AUDIT: review exclusions # Tampering with these (esp. adding exclusions) is a key detection
DETECTION-ENGINEERING ANGLE#
# For each evasion class, ensure you have a detection: # AMSI patch -> AMSI/Defender tamper alerts + 4104 # ETW blinding -> stream-gap analytics, memory integrity # Unhooking -> unbacked-memory + syscall-origin analytics # Injection -> cross-proc write + RWX + remote thread # Defender tamper -> MpPreference exclusion/RTP-disable events # Validate with Atomic Red Team / purple-team runs
EXAMPLES#
# Audit Defender exclusions across a fleet (blue team) Get-MpPreference | Select-Object -ExpandProperty ExclusionPath # Confirm real-time protection and tamper protection are on Get-MpComputerStatus | Select RealTimeProtectionEnabled,IsTamperProtected # Purple-team validation of AMSI/injection detections # (run known-benign Atomic Red Team tests, verify alerts fire)
NOTES#
- This sheet intentionally stays at the category/telemetry level - the goal is detection coverage, not shipping an evasive loader - Tamper Protection (Defender) blocks most Set/Add-MpPreference abuse; verify it is enabled on FS endpoints - The strongest defensive posture: kernel telemetry (callbacks) + Sysmon + AMSI + PowerShell logging, correlated in the SIEM - Track EDR "blind spots" as findings mapped to DORA ICT risk and NIS2 detection-capability requirements - Pair with LOLBAS.txt, DETECTION-ENGINEERING.txt, DEFENDER-KQL.txt