Ross ROSS = Recommend OSS · open-source software intelligence for agents

wavestone-cdt/EDRSandblast

None observed · 2026-08-28

github.com/wavestone-cdt/EDRSandblast · C observed · 2026-08-28

Health v2 · maintenance only

32/100

  • Activity 0
  • Release rhythm 35
  • Longevity 100

Flags: no_releases no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 1765
  • days_rel: n/a
  • days_push: 733
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

1844 stars · 318 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

EDRSandBlast is a C-based offensive security tool that weaponizes vulnerable signed drivers to bypass EDR detections on Windows, including kernel notify routine callbacks, object callbacks, and ETW Threat Intelligence providers. It also implements userland unhooking techniques to evade userland monitoring, enabling actions like LSASS memory dumping without generating detection events.

Use cases

  • bypass EDR kernel callbacks to dump LSASS credentials
  • remove EDR notify routines from the Windows kernel
  • unhook EDR userland DLL hooks before running tooling
  • disable ETW Threat Intelligence logging during red team operations
  • test EDR product resilience against kernel-level evasion
  • strip LSASS process protection (PPL) via kernel write primitives

When to choose

  • you are a red teamer needing to evade EDR during credential access on Windows
  • you are a security researcher studying EDR kernel callback mechanisms
  • you need to evaluate how well an EDR detects kernel-mode evasion techniques

When to avoid

  • you need a defensive tool to harden systems against such attacks
  • you want a general-purpose penetration testing framework
  • you need cross-platform support outside Windows
  • you require a maintained tool with an explicit license for production use

Facets

cli-tool · maturity maintenance

security penetration-testing reverse-engineering security penetration-testing windows windows cli edr-bypass red-team kernel-exploitation lsass-dumping offensive-security vulnerable-driver etw-patching userland-unhooking

1 source

Member repositories

RepositoryRoleHealth v2
wavestone-cdt/EDRSandblastmain32

For agents

markdown · JSON · MCP: product_card(name="wavestone-cdt/EDRSandblast")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem