# tkmru/awesome-edr-bypass

Awesome EDR Bypass Resources For Ethical Hacking

Repository: https://github.com/tkmru/awesome-edr-bypass
Canonical: https://ross.abutalabs.com/products/awesome-edr-bypass
License Family: other
Topics: awesome-lists, edr, edr-bypass, redteam, redteaming
Last push: 2026-01-26T18:06:04+00:00

## Health v2 (maintenance only)
Score: 59/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 64, release rhythm 35, longevity 88
- inputs: {"age_days": 1232, "days_push": 219, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases, no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1585, forks 153 (observed 2026-08-28T04:05:07.540209+00:00)

## What it is
A curated awesome-list of resources, proof-of-concept code, and tools for bypassing Endpoint Detection and Response (EDR) software, aimed at ethical hacking, penetration testing, and incident response education. It aggregates links to techniques like direct syscalls, API unhooking, and EDR telemetry blocking.

## Use cases
- find resources on EDR bypass techniques for red team engagements
- learn how malware evades endpoint detection and response tools
- research syscall unhooking and direct syscall techniques
- test the detection accuracy of an EDR product
- prepare for offensive security certifications or pentest work
- understand attacker tradecraft as an incident responder

## When to choose
- you need a curated starting point for EDR evasion research
- you are a red teamer or pentester studying detection bypass techniques
- you are a defender or incident responder wanting to understand attacker methods

## When to avoid
- you need a ready-to-use production security tool rather than a link collection
- you want defensive EDR software itself
- you lack authorization for offensive security testing, as misuse is illegal

## Facets
- artifact type: learning-resource
- maturity: active
- function: security, penetration-testing, developer-tools
- domain: security, penetration-testing, awesome-lists, reverse-engineering
- platform: windows, cross-platform
- tags: awesome-list, edr-bypass, red-team, ethical-hacking, curated-resources, offensive-security

## Member repositories
- tkmru/awesome-edr-bypass (main) score 59

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:05:07.540209+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T03:55:39.593307+00:00, confidence not recorded.
  - readme: https://github.com/tkmru/awesome-edr-bypass (fetched 2026-08-28T04:05:07.540209+00:00, sha 600bbdaf4068)
- Data as of 2026-08-30T08:39:29.467469+00:00.
