wavestone-cdt/EDRSandblast
None observed · 2026-08-28
Health v2 · maintenance only
32/100
- Activity 0
- Release rhythm 35
- Longevity 100
Flags: no_releases no_license
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: n/a
- age_days: 1765
- days_rel: n/a
- days_push: 733
- n_releases_24m: 0
Adoption not part of the score
1844 stars · 318 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
EDRSandBlast is a C-based offensive security tool that weaponizes vulnerable signed drivers to bypass EDR detections on Windows, including kernel notify routine callbacks, object callbacks, and ETW Threat Intelligence providers. It also implements userland unhooking techniques to evade userland monitoring, enabling actions like LSASS memory dumping without generating detection events.
Use cases
- bypass EDR kernel callbacks to dump LSASS credentials
- remove EDR notify routines from the Windows kernel
- unhook EDR userland DLL hooks before running tooling
- disable ETW Threat Intelligence logging during red team operations
- test EDR product resilience against kernel-level evasion
- strip LSASS process protection (PPL) via kernel write primitives
When to choose
- you are a red teamer needing to evade EDR during credential access on Windows
- you are a security researcher studying EDR kernel callback mechanisms
- you need to evaluate how well an EDR detects kernel-mode evasion techniques
When to avoid
- you need a defensive tool to harden systems against such attacks
- you want a general-purpose penetration testing framework
- you need cross-platform support outside Windows
- you require a maintained tool with an explicit license for production use
Facets
cli-tool · maturity maintenance
security penetration-testing reverse-engineering security penetration-testing windows windows cli edr-bypass red-team kernel-exploitation lsass-dumping offensive-security vulnerable-driver etw-patching userland-unhooking
1 source
- readme: https://github.com/wavestone-cdt/EDRSandblast · fetched 2026-08-28 · 7aef80f6c717
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| wavestone-cdt/EDRSandblast | main | 32 |
For agents
markdown · JSON · MCP: product_card(name="wavestone-cdt/EDRSandblast")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem