Agent skill

Re Evasion

by dslsdzc in dslsdzc/rev-skills

检测规避/EDR 对抗分析:AMSI/ETW 绕过、无文件、lolbin 链. An agent skill from dslsdzc/rev-skills.

Apache-2.0Auto-check passedSecurity

Install Re Evasion

skills CLI
$ npx skills add dslsdzc/rev-skills --skill re-evasion -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install dslsdzc/rev-skills re-evasion --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/re-evasion .claude/skills/re-evasion && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
re-evasion
GitHub stars
130
Token cost
~1.6k tokens
SKILL.md length
430 words
Files
1
Skills in repo
40
Repo updated
First seen
Licence
Apache-2.0

At a glance

检测规避/EDR 对抗分析:AMSI/ETW 绕过、无文件、lolbin 链. An agent skill from dslsdzc/rev-skills.

  • Works in 5 steps: 规避手段识别(先分类再深入) → AMSI 绕过分析(内存 patch 定位) → ETW 禁用分析 → …
  • Security work in your project
  • SKILL.md covers 何时使用 / 何时不用, 工具准备, 操作步骤 and 跨域联合, plus 1 more section
  • Calls winget

What it does

Re Evasion is an agent skill from dslsdzc/rev-skills. 检测规避/EDR 对抗分析:AMSI/ETW 绕过、无文件、lolbin 链。 触发词:规避、evasion、AMSI、ETW、无文件、lolbin、EDR绕过

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security. It works with GitHub. The repository describes itself as: 122 个逆向工程 AI 技能(可发布、跨平台):恶意软件分析 / 软件逆向 / 固件嵌入式 / 协议逆向 / 移动应用 / 脱壳反混淆 / 软件破解 / 漏洞挖掘 / 托管代码 / 取证情报 / CTF。 The licence is Apache-2.0.

When your agent uses it

  • Security work in your project

Example prompts

  • “/re-evasion”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. 规避手段识别(先分类再深入)
  2. AMSI 绕过分析(内存 patch 定位)
  3. ETW 禁用分析
  4. lolbin 链追踪(rundll32/mshta 等)
  5. 与检测侧对齐(为什么被检测 → 规避点)

What it can do on your machine

Read from SKILL.md and the folder at commit bd21db8. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • winget

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Re Evasion loads about 1.6k tokens when it runs. Until then it costs about 23 tokens; SKILL.md has 430 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~23
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from dslsdzc/rev-skills at commit bd21db8, republished under its Apache-2.0 licence (© dslsdzc). 430 words, ~1,558 tokens.

Download SKILL.mdSave it as .claude/skills/re-evasion/SKILL.md (or your agent's skills folder).
name
re-evasion
description
检测规避/EDR 对抗分析:AMSI/ETW 绕过、无文件、lolbin 链。 触发词:规避、evasion、AMSI、ETW、无文件、lolbin、EDR绕过
capabilities
evasion-analysis

检测规避与 EDR 对抗分析

何时使用 / 何时不用

  • 用:恶意样本/工具被检测(杀软、EDR)后分析其规避手段——AMSI 绕过、ETW 禁用、无文件执行、lolbin 链
  • 用:回答"为什么被检测"与"绕过点在哪"(与检测侧对齐,步骤 5)
  • 用:无文件/内存载荷的执行链分析(载荷不落盘的样本)
  • 不用:纯静态代码分析(那是 [[re-binary-core]]);不关心绕过机制、只观察行为的动态分析(那是 [[re-behavior]])
  • 不用:检测规则编写本身(那是 [[re-ioc]] 的 YARA 与检测工程侧)
  • 注意:本技能以 Windows 为主(AMSI/ETW/lolbin 均为 Windows 概念);Linux/macOS 的类似对抗(ptrace 检测、Dyld 注入、kext 绕过)按同一"规避识别→绕过点定位"框架套用

工具准备

规避分析必须动态执行 + 内存取证:全程在沙箱内([[re-sandbox]] 强制前置,[[re-analyze/platform-tips]] 最高原则)。所有工具先验证再使用。

amsi.dll 内存对照 —— AMSI patch 定位主力(无独立安装包)
  • 原理: 磁盘 C:\Windows\System32\amsi.dll 与内存中的 amsi.dll 逐字节对照,函数头差异即 patch 点
  • 取内存拷贝: Sysinternals procdump(微软官网/winget install Microsoft.Sysinternals.Procdump)procdump -accepteula -ma <pid> mem.dmp;或 [[re-memdump]](gcore/WSL)全量转储
  • 验证: 对未运行样本的场景用 AMSITrigger 兜底;对照脚本见步骤 2
AMSITrigger —— 定位触发 AMSI 扫描的字符串(Outflank 出品)
  • 下载: GitHub 检索 AMSITrigger(原 outflanknl 仓库已不可用,社区镜像常见,如 RythmStick/AMSITrigger);.NET 工具,解压即用
  • 验证: AMSITrigger.exe -i test.ps1 输出逐行触发状态(Detected / Not Detected)
  • 用途: 分析"脚本里哪些字符串触发检测"→ 对应混淆/规避目标
ETW 监控 —— logman / SilkETW / WPR / ETWConsumer 类工具
  • logman(Windows 内置): 验证 logman query providers | findstr /i sysmon;logman query -ets 看活动会话
  • SilkETW(Mandiant 开源,C#): GitHub releases 下载;验证: SilkETW.exe -t user -pn Microsoft-Windows-Sysmon -ot file -p out.etl 能生成 .etl
  • WPR(Windows Performance Recorder,内置): wpr -start 后 wpr -stop out.etl
  • ETWConsumer 等第三方 ETW 消费者工具(GitHub 检索,按需);本机看 provider 的替代: tracerpt 解析 .etl
  • 用途: 确认 ETW 是否被禁——事件流中断/缺失即禁用证据(见步骤 3)
Sysmon / procmon —— 进程链与执行行为(lolbin 链追踪)
  • Sysmon(Sysinternals,微软官方): 配置含 ProcessCreate(事件 1,记录父子进程与命令行);验证: Get-WinEvent -FilterHashtable @{LogName='Microsoft-Windows-Sysmon/Operational';Id=1} | select -First 1
  • procmon(Sysinternals): 文件/注册表/进程/网络全量,可按进程树过滤;验证: procmon.exe /AcceptEula /Quiet 能启动
  • 二者均无发行版包,从微软官网/Sysinternals 下载

操作步骤

按顺序执行,每步产物(内存转储/ETL/日志/命令行走访记录)存档 sha256 + 路径([[re-ioc]] 证据链要求)。

  1. 规避手段识别(先分类再深入):

    • 输入: 样本/工具 + 检测触发信息(杀软告警、EDR 日志、沙箱告警)
    • 分类清单(按特征归档): AMSI 绕过(patch / 反射加载)、ETW 禁用(patch provider / 掩码)、无文件(内存执行 / 注册表运行键 + 远程脚本 / WMI)、lolbin 链(rundll32 / mshta / regsvr32 / WMI / PowerShell)、字符串编码混淆(防特征)
    • 证据采集: 沙箱内运行([[re-sandbox]])→ Sysmon/procmon 记录进程创建链与命令行;同时 [[re-memdump]] 留内存快照(默认转储优先,[[re-analyze/platform-tips]]「直读 vs 转储」);PowerShell 开启 ScriptBlock 日志(事件 4104)与模块日志
    • 先跑一遍不 patch 的基准样本确认"检测触发点"(见坑 5 与步骤 5 对齐)
  2. AMSI 绕过分析(内存 patch 定位):

    sh
    procdump -accepteula -ma <pid> mem.dmp        # 运行后取进程内存(或 gcore,见 [[re-memdump]])
    # 对照: 磁盘 amsi.dll 与内存中 amsi.dll 的函数头字节
    # 常见 patch: AmsiScanBuffer 入口改为直接返回 0x80070057("AMSI 已初始化"假成功)
    #            或 EtwEventWrite 系列前几字节 patch 成 ret
    • 定位法: 磁盘 amsi.dll 里 AmsiScanBuffer 的入口偏移(Ghidra/IDA 或 dumpbin /exports)→ 内存 dump 同偏移字节对照;有差异即 patch 点
    • 其他形式: 反射加载 amsi.dll 前 hook(Detour 到用户代码)、CLR 侧绕过(托管层关闭 AMSI provider)
    • 用 AMSITrigger 验证"哪些字符串触发"→ 样本混淆目标与绕过有效性互证
    • patch 定位前确认环境基线: 不运行样本时磁盘/内存 amsi.dll 一致(排除 EDR 自身 hook 干扰,见坑 4)
  3. ETW 禁用分析:

    sh
    logman query -ets                                   # 活动会话;与样本运行前后对比
    # SilkETW 捕获: 运行样本前后各抓一段,对比事件数量/内容
    # 定位: 内存中 ntdll 的 EtwEventWrite / EtwEventWriteEx 前几字节 vs 磁盘(同步骤 2 对照法)
    • 禁用证据: 样本运行后 ETW 事件流中断(某 provider 零事件/整体丢失);patch 点通常位于 ntdll 的 EtwEventWrite*
    • 确认范围: 全局禁用(改 EtwEventWrite 本身)vs 特定 provider 禁用(改 provider 的 enable 掩码/Level)——决定影响面与检测侧恢复建议
    • 与 AMSI 常组合出现(一个 patch 多个目标),对照报告两者联动(见坑 1)
  4. lolbin 链追踪(rundll32/mshta 等):

    sh
    # Sysmon 事件 1(ProcessCreate)按进程树关联,重点看父进程 + 命令行
    Get-WinEvent -FilterHashtable @{LogName='Microsoft-Windows-Sysmon/Operational';Id=1} |
      Select TimeCreated, @{n='Parent';e={$_.Properties[1].Value}}, @{n='Image';e={$_.Properties[3].Value}}, @{n='Cmd';e={$_.Properties[4].Value}}
    • 典型链: cmd → rundll32.exe javascript:"..."、regsvr32.exe /s /n /u /i:http://... scrobj.dll、mshta.exe javascript:...、powershell -enc ... → 内存载荷
    • 关键: 只看样本自身进程会漏掉真实行为(样本借道白名单进程执行——见 [[re-sandbox]] 的 brokered execution 坑);按整条进程树观察,父→子逐级记录
    • 无文件判定: 进程映像路径非常规(%TEMP%)、脚本引擎(wscript/cscript/mshta)加载远程或纯内存内容、无对应磁盘文件——载荷证据靠内存转储与命令行(见坑 3)
  5. 与检测侧对齐(为什么被检测 → 规避点):

    • 把检测告警命中的内容(触发字符串/行为签名/导入表特征)与步骤 2-4 的证据对照,形成: 检测点(杀软签名/行为规则)→ 规避点(patch/混淆/lolbin)→ 仍可被检测的缺口(见坑 4 版本差异)
    • 输出: 规避手法清单 + 对应 IOC——内存 patch 后 amsi.dll/ntdll 的哈希、lolbin 组合的命令行模式、无文件载荷的内存特征(进 [[re-ioc]] YARA)
    • 结论必须标注验证环境(OS 版本/EDR 版本/杀软),规避有效性声明带版本限定
Show full SKILL.md (95 more words)Show less

跨域联合

  • [[re-anti-analysis]]:本技能是该网关的检测规避分支——壳/混淆是"静态反分析",AMSI/ETW/无文件是"检测对抗",编排上并列
  • [[re-sandbox]]:动态执行强制前置——规避分析全程在隔离环境(网络隔离 + 快照,见 [[re-analyze/platform-tips]] 最高原则)
  • [[re-memdump]]:内存 patch 定位与无文件载荷取证(默认转储优先)
  • [[re-behavior]]:进程链/执行行为观察(lolbin 链的行为侧佐证)
  • [[re-tracing]]:API 调用跟踪——patch 目标函数(AmsiScanBuffer/EtwEventWrite)的调用序列佐证绕过是否生效
  • [[re-ioc]]:规避特征(内存哈希/命令行模式/lolbin 组合)进 IOC 与 YARA 规则
  • [[re-malware]]:恶意样本的规避层分析(re-malware 行为分析后转本技能深挖规避)
  • [[re-ebpf]]:驻留 bpf hook(fentry/kprobe/tracepoint/cgroup)的识别与反制
  • 引用 [[re-analyze/platform-tips]] 最高原则(默认沙箱)与 Windows 分支

常见坑与陷阱

  • 规避手段与反沙箱交织:现象——沙箱里样本表现"正常"(无任何规避动作),真实环境才绕过;原因——规避代码里夹反沙箱检测(先探测环境再决定是否启用绕过);对策——把"规避分析"与"环境伪装"分开([[re-anti-analysis]] 域):先定位反沙箱检测点([[re-sandbox]] 的交互/时间/硬件指纹坑),或先按 [[re-behavior]] 的延迟观察拉长窗口,再分析规避逻辑
  • AMSI patch 触发完整性校验:现象——patch 后样本行为异常/崩溃/检测反而升级;原因——EDR/Defender 校验 amsi.dll/ntdll 内存完整性(与磁盘比对哈希,见 [[re-anti-analysis]] AD13 自校验思路),或样本自身做自校验;对策——先确认校验存在(重复比对内存哈希频率),patch 改"校验看不见"的位置(hook 而非函数体、保持整体哈希一致),分析时记录 patch 时机与校验触发点
  • 无文件样本取证难:现象——磁盘上没有样本文件,报告无"物证",结论站不住;原因——载荷全程在内存/远程脚本/注册表运行键,常规文件取证抓不到;对策——运行前先 [[re-memdump]] 全量转储 + procmon/Sysmon 记录命令行与网络;PowerShell 开 ScriptBlock 日志(事件 4104);结论以内存证据 + 命令行 + 网络流为准,[[re-ioc]] 收内存哈希类特征
  • EDR 版本差异:现象——同一 patch 手法在环境 A 成功、环境 B 失效或告警;原因——patch 偏移(如 AmsiScanBuffer 入口字节)随 Windows 补丁与 EDR hook 版本变化;对策——动态现场确认偏移(步骤 2 的内存对照法不依赖固定偏移,别信网上的硬编码偏移);结论标注验证环境版本,规避有效性声明带版本限定
  • 检测日志缺失 → 方向错误:现象——没有 Sysmon/EDR 日志,无法确认"为什么被检测",分析无从对齐;原因——环境未配置日志采集(默认 Windows 不记录 ProcessCreate 细节);对策——补 Sysmon 配置(ProcessCreate + NetworkConnect + ImageLoad)+ PowerShell 4104,重跑复现;检测告警信息(杀软界面/EDR 事件)先截全再分析

© dslsdzc, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/re-evasion of dslsdzc/rev-skills.

Open the folder on GitHubat commit bd21db8

Compare with similar skills

Re Evasion next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Re Evasion compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Re Evasion this skilldslsdzc/rev-skills130—~1.6kAutomated safety check: PassApache-2.0
ReleaseZeecka/AperiSolve852—~1.9kAutomated safety check: PassMIT
Triage Codeqlnetdata/netdata81k—~1.8kAutomated safety check: NotesGPL-3.0
Security AdvisoryMidnightBSD/src114—~2.2kAutomated safety check: PassCustom licence
Security Vulnerability Analysiseclipse-ankaios/ankaios125—~1.5kAutomated safety check: PassApache-2.0
Agentic GitHub Actions Auditortrailofbits/skills7.4k6 repos~5.4kAutomated safety check: NotesCC-BY-SA-4.0

Similar skills

  • Release

    Zeecka/AperiSolve

    Cut a new AperiSolve release — bump the version, commit "chore(release): X.Y.Z", tag it, push, and publish a GitHub Release whose notes are computed from the commits since the last tag.

    852 GitHub stars~1.9k tokensUpdated 2 days ago
    SecurityAuto-check passed
  • Triage Codeql

    netdata/netdata

    Inspect, review or triage GitHub Code Scanning alerts, including CodeQL findings; apply verified dismissals when authorized.

    81k GitHub stars~1.8k tokensUpdated today
    SecurityAuto-check: notes
  • Security Advisory

    MidnightBSD/src

    Handle a security fix end to end for MidnightBSD src - triage a FreeBSD security advisory (FreeBSD-SA-) or CVE against this tree, port the fix to master and both stable branches, add the UPDATING…

    114 GitHub stars~2.2k tokensUpdated 5 days ago
    SecurityAuto-check passed
  • Security Vulnerability Analysis

    eclipse-ankaios/ankaios

    Analyze potential Ankaios security vulnerabilities from pasted reports, local evidence, or advisory URLs.

    125 GitHub stars~1.5k tokensUpdated yesterday
    SecurityAuto-check passed
  • Official

    Statically audits GitHub Actions workflows that run AI coding agents, tracing attacker-controlled input to agent prompts and flagging unsafe sandbox, trigger and allowlist settings.

    7.4k GitHub starsUsed in 6 repos~5.4k tokens
    SecurityAuto-check: notes
  • A skill your agent uses when a researcher, maintainer, or contributor found or suspects a malicious skill on ClawHub and needs a private reporting workflow: opening a GitHub private vulnerability…

    143 GitHub stars~1.1k tokensUpdated 2 days ago
    SecurityAuto-check passed

More from dslsdzc/rev-skills

All 40 skills in this repo
  • Captures an analyzable sample from a live system when the target leaves no file on disk, by finding abnormal executable memory and the execution context that reached it.

    130 GitHub stars~2k tokensUpdated 4 days ago
    Auto-check passed
  • APK Static Analysis

    dslsdzc/rev-skills

    Guides static analysis of an Android APK with jadx and apktool: reading the manifest, Java code, resources and permissions, and recognizing hardening or obfuscation.

    130 GitHub stars~2k tokensUpdated 4 days ago
    Auto-check passed
  • Re Attribution

    dslsdzc/rev-skills

    威胁归因方法论:钻石模型、基础设施图谱、置信度分级与归因报告. An agent skill from dslsdzc/rev-skills.

    130 GitHub stars~1.1k tokensUpdated 4 days ago
    Auto-check passed
  • Re Format Elf

    dslsdzc/rev-skills

    ELF 格式解析:ehdr/phdr/shdr、GOT/PLT、initarray、符号恢复. An agent skill from dslsdzc/rev-skills.

    130 GitHub stars~1.9k tokensUpdated 4 days ago
    Auto-check passed
  • Re Fp Runtime

    dslsdzc/rev-skills

    函数式语言运行时逆向(Haskell/OCaml):闭包/堆对象模型、调用约定、数据流优先策略. An agent skill from dslsdzc/rev-skills.

    130 GitHub stars~1.4k tokensUpdated 4 days ago
    Auto-check passed
  • Re Frida

    dslsdzc/rev-skills

    Frida 动态插桩(桌面+移动统一). An agent skill from dslsdzc/rev-skills.

    130 GitHub stars~2.8k tokensUpdated 4 days ago
    Auto-check passed

Works with

Questions about Re Evasion

What does Re Evasion do?

检测规避/EDR 对抗分析:AMSI/ETW 绕过、无文件、lolbin 链. An agent skill from dslsdzc/rev-skills. Re Evasion is an agent skill from dslsdzc/rev-skills.

When should I use Re Evasion?

Re Evasion fits situations like: security work in your project.

How do I install Re Evasion in Claude Code?

Run `npx skills add dslsdzc/rev-skills --skill re-evasion -a claude-code`. Or copy the skill folder (.claude/skills/re-evasion in dslsdzc/rev-skills) into .claude/skills/re-evasion in your project. Claude Code loads it when a task matches its description.

How do I install Re Evasion in Codex?

Run `npx skills add dslsdzc/rev-skills --skill re-evasion -a codex`. Or copy the skill folder (.claude/skills/re-evasion in dslsdzc/rev-skills) into .agents/skills/re-evasion in your project. Codex loads it when a task matches its description.

Can I use Re Evasion in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add dslsdzc/rev-skills --skill re-evasion -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/re-evasion, .gemini/skills/re-evasion, .github/skills/re-evasion and .opencode/skills/re-evasion in your project.

What does Re Evasion need to run?

Going by SKILL.md and its folder, Re Evasion needs the command-line tools its instructions call (winget).

Does Re Evasion access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Re Evasion safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Re Evasion use?

Re Evasion is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Re Evasion use?

About 1.6k tokens (SKILL.md is roughly 6.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Re Evasion?

Skills that share tags, products or a category with Re Evasion: Release (Zeecka/AperiSolve, 852 stars), Triage Codeql (netdata/netdata, 81k stars), Security Advisory (MidnightBSD/src, 114 stars) and Security Vulnerability Analysis (eclipse-ankaios/ankaios, 125 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Re Evasion?

dslsdzc (a GitHub user) maintains it in dslsdzc/rev-skills, which has 130 GitHub stars. The repository holds 40 skills in this directory. The repository was last updated on October 5, 2026.

Source: dslsdzc/rev-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.