{"adoption": {"forks": 1251, "observed_at": "2026-08-28T04:09:10.894213+00:00", "stars": 5120}, "canonical_url": "https://ross.abutalabs.com/products/bypassantivirus", "card": {"archived": false, "artifact_type": "learning-resource", "description": "远控免杀系列文章及配套工具，汇总测试了互联网上的几十种免杀工具、113种白名单免杀方式、8种代码编译免杀、若干免杀实战技术，并对免杀效果进行了一一测试，为远控的免杀和杀软对抗免杀提供参考。", "domain": ["security", "penetration-testing", "tutorials"], "enriched": true, "function": ["security", "penetration-testing", "developer-tools"], "health_score": 20, "homepage": null, "language": "XSLT", "license": null, "license_family": "other", "maturity": "maintenance", "member_repos": ["TideSec/BypassAntiVirus", "TideSec/GoBypassAV"], "name": "BypassAntiVirus", "platform": ["windows", "cross-platform"], "pushed_at": "2024-09-14T16:43:27+00:00", "repo": "TideSec/BypassAntiVirus", "stars": 5120, "tags": ["antivirus-evasion", "red-team", "shellcode", "living-off-the-land", "malware-analysis", "offensive-security"], "topics": [], "urls": [], "use_cases": ["learn how antivirus evasion techniques work", "find tools to test shellcode evasion against AV engines", "study LOLBin whitelist payload loading techniques", "compare effectiveness of AV bypass tools like Veil, Shellter, TheFatRat", "prepare for red team engagements and AV/EDR evasion testing", "research compile-based evasion in C/C++, C#, Python, Go, PowerShell"], "what_it_is": "A Chinese-language knowledge base and tool collection on antivirus evasion (bypassing AV) for remote access payloads, summarizing dozens of evasion tools, 113 living-off-the-land whitelist techniques, and code-compile evasion methods with test results. It serves as a reference for red teamers and security researchers studying AV detection and evasion.", "when_to_avoid": ["you need a production-ready evasion tool rather than educational material", "you want defensive/EDR detection guidance instead of offensive techniques", "you require a maintained tool with a license and active development"], "when_to_choose": ["you need a curated survey of AV evasion tools and techniques with test results", "you are studying offensive security or red team AV bypass methods", "you want a reference of whitelist (LOLBin) payload loading techniques"]}, "data_as_of": "2026-08-30T08:39:29.467469+00:00", "members": [{"path": "/repos/TideSec/BypassAntiVirus", "repo": "TideSec/BypassAntiVirus", "role": "main", "score": 32}, {"path": "/repos/TideSec/GoBypassAV", "repo": "TideSec/GoBypassAV", "role": "examples", "score": 32}], "provenance": {"archived": {"kind": "observed", "observed_at": "2026-08-28T04:09:10.894213+00:00", "source": "github"}, "artifact_type": {"confidence": null, "enriched_at": "2026-08-29T18:02:05.875101+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "95121b703a1d3291ac408c69069be52ab14b7277167497b3666123e7882b8305", "fetched_at": "2026-08-28T04:09:10.894213+00:00", "kind": "readme", "missing": false, "url": "https://github.com/TideSec/BypassAntiVirus"}], "taxonomy_version": 1}, "description": {"kind": "observed", "observed_at": "2026-08-28T04:09:10.894213+00:00", "source": "github"}, "domain": {"confidence": null, "enriched_at": "2026-08-29T18:02:05.875101+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "95121b703a1d3291ac408c69069be52ab14b7277167497b3666123e7882b8305", "fetched_at": "2026-08-28T04:09:10.894213+00:00", "kind": "readme", "missing": false, "url": "https://github.com/TideSec/BypassAntiVirus"}], "taxonomy_version": 1}, "enriched": {"inputs": [], "kind": "computed", "method": "enrichment_status"}, "function": {"confidence": null, "enriched_at": "2026-08-29T18:02:05.875101+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "95121b703a1d3291ac408c69069be52ab14b7277167497b3666123e7882b8305", "fetched_at": "2026-08-28T04:09:10.894213+00:00", "kind": "readme", "missing": false, "url": "https://github.com/TideSec/BypassAntiVirus"}], "taxonomy_version": 1}, "health_score": {"inputs": ["days_since_push", "days_since_release", "archived"], "kind": "computed", "method": "health_v1"}, "homepage": {"kind": "observed", "observed_at": "2026-08-28T04:09:10.894213+00:00", "source": "github"}, "language": {"kind": "observed", "observed_at": "2026-08-28T04:09:10.894213+00:00", "source": "github"}, "license": {"kind": "observed", "observed_at": "2026-08-28T04:09:10.894213+00:00", "source": "github"}, "license_family": {"inputs": ["license"], "kind": "computed", "method": "license_family"}, "maturity": {"confidence": null, "enriched_at": "2026-08-29T18:02:05.875101+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "95121b703a1d3291ac408c69069be52ab14b7277167497b3666123e7882b8305", "fetched_at": "2026-08-28T04:09:10.894213+00:00", "kind": "readme", "missing": false, "url": "https://github.com/TideSec/BypassAntiVirus"}], "taxonomy_version": 1}, "member_repos": {"kind": "observed", "observed_at": "2026-08-28T04:09:10.894213+00:00", "source": "github"}, "name": {"kind": "observed", "observed_at": "2026-08-28T04:09:10.894213+00:00", "source": "github"}, "platform": {"confidence": null, "enriched_at": "2026-08-29T18:02:05.875101+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "95121b703a1d3291ac408c69069be52ab14b7277167497b3666123e7882b8305", "fetched_at": "2026-08-28T04:09:10.894213+00:00", "kind": "readme", "missing": false, "url": "https://github.com/TideSec/BypassAntiVirus"}], "taxonomy_version": 1}, "pushed_at": {"kind": "observed", "observed_at": "2026-08-28T04:09:10.894213+00:00", "source": "github"}, "repo": {"kind": "observed", "observed_at": "2026-08-28T04:09:10.894213+00:00", "source": "github"}, "stars": {"kind": "observed", "observed_at": "2026-08-28T04:09:10.894213+00:00", "source": "github"}, "tags": {"confidence": null, "enriched_at": "2026-08-29T18:02:05.875101+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "95121b703a1d3291ac408c69069be52ab14b7277167497b3666123e7882b8305", "fetched_at": "2026-08-28T04:09:10.894213+00:00", "kind": "readme", "missing": false, "url": "https://github.com/TideSec/BypassAntiVirus"}], "taxonomy_version": 1}, "topics": {"kind": "observed", "observed_at": "2026-08-28T04:09:10.894213+00:00", "source": "github"}, "urls": {"kind": "observed", "observed_at": "2026-08-28T04:09:10.894213+00:00", "source": "github"}, "use_cases": {"confidence": null, "enriched_at": "2026-08-29T18:02:05.875101+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "95121b703a1d3291ac408c69069be52ab14b7277167497b3666123e7882b8305", "fetched_at": "2026-08-28T04:09:10.894213+00:00", "kind": "readme", "missing": false, "url": "https://github.com/TideSec/BypassAntiVirus"}], "taxonomy_version": 1}, "what_it_is": {"confidence": null, "enriched_at": "2026-08-29T18:02:05.875101+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "95121b703a1d3291ac408c69069be52ab14b7277167497b3666123e7882b8305", "fetched_at": "2026-08-28T04:09:10.894213+00:00", "kind": "readme", "missing": false, "url": "https://github.com/TideSec/BypassAntiVirus"}], "taxonomy_version": 1}, "when_to_avoid": {"confidence": null, "enriched_at": "2026-08-29T18:02:05.875101+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "95121b703a1d3291ac408c69069be52ab14b7277167497b3666123e7882b8305", "fetched_at": "2026-08-28T04:09:10.894213+00:00", "kind": "readme", "missing": false, "url": "https://github.com/TideSec/BypassAntiVirus"}], "taxonomy_version": 1}, "when_to_choose": {"confidence": null, "enriched_at": "2026-08-29T18:02:05.875101+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "95121b703a1d3291ac408c69069be52ab14b7277167497b3666123e7882b8305", "fetched_at": "2026-08-28T04:09:10.894213+00:00", "kind": "readme", "missing": false, "url": "https://github.com/TideSec/BypassAntiVirus"}], "taxonomy_version": 1}}, "score": {"components": {"activity": 0, "longevity": 100, "rhythm": 35}, "computed_at": "2026-09-02T17:46:02.011165+00:00", "flags": ["no_releases", "no_license"], "formula": "round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)", "inputs": {"age_days": 2452, "days_push": 718, "days_rel": null, "gap_med": null, "n_releases_24m": 0}, "score": 32, "version": 2}, "staleness": {"enrichment_outdated": false, "low_confidence": false, "scrape_days": 9, "stale_scrape": false}}