{"adoption": {"forks": 246, "observed_at": "2026-08-28T04:05:51.402662+00:00", "stars": 1899}, "canonical_url": "https://ross.abutalabs.com/products/edrsilencer", "card": {"archived": false, "artifact_type": "cli-tool", "description": "A tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the server.", "domain": ["security", "penetration-testing", "windows"], "enriched": true, "function": ["security", "networking", "cli"], "health_score": 29, "homepage": null, "language": "C", "license": "MIT", "license_family": "permissive", "maturity": "active", "member_repos": ["netero1010/EDRSilencer"], "name": "netero1010/EDRSilencer", "platform": ["windows", "cli"], "pushed_at": "2024-11-03T16:05:14+00:00", "repo": "netero1010/EDRSilencer", "stars": 1899, "tags": ["edr-evasion", "wfp", "red-team", "offensive-security", "traffic-blocking", "c2"], "topics": [], "urls": [], "use_cases": ["block edr agents from reporting to their server", "silence endpoint detection and response telemetry during red team ops", "add wfp filters to block outbound traffic of a specific process", "enumerate running edr processes on a windows host", "remove wfp filters created by the tool", "test edr resilience against traffic blocking"], "what_it_is": "A C-based Windows command-line tool that uses Windows Filtering Platform (WFP) APIs to block outbound traffic of running EDR agents, preventing them from reporting security events to their servers. It supports many commercial EDR products and can be executed in-memory from C2 frameworks.", "when_to_avoid": ["you need a defensive tool to protect or monitor EDR agents", "you require stealth features or C2 integration beyond in-memory PE execution", "your target platform is not Windows 10 or Windows Server 2016+"], "when_to_choose": ["you are a red teamer or penetration tester needing to suppress EDR alerting during authorized engagements", "you need a lightweight open-source alternative to commercial tools like FireBlock", "you want to block outbound traffic of arbitrary processes via WFP on Windows"]}, "data_as_of": "2026-08-30T08:39:29.467469+00:00", "members": [{"path": "/products/edrsilencer", "repo": "netero1010/EDRSilencer", "role": "main", "score": 17}], "provenance": {"archived": {"kind": "observed", "observed_at": "2026-08-28T04:05:51.402662+00:00", "source": "github"}, "artifact_type": {"confidence": null, "enriched_at": "2026-08-30T03:12:11.507082+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "79f1af32a8bedc1da1f5d9b9c378764b0beadf40f708f4fd8f6aeace223fe0e7", "fetched_at": "2026-08-28T04:05:51.402662+00:00", "kind": "readme", "missing": false, "url": "https://github.com/netero1010/EDRSilencer"}], "taxonomy_version": 1}, "description": {"kind": "observed", "observed_at": "2026-08-28T04:05:51.402662+00:00", "source": "github"}, "domain": {"confidence": null, "enriched_at": "2026-08-30T03:12:11.507082+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "79f1af32a8bedc1da1f5d9b9c378764b0beadf40f708f4fd8f6aeace223fe0e7", "fetched_at": "2026-08-28T04:05:51.402662+00:00", "kind": "readme", "missing": false, "url": "https://github.com/netero1010/EDRSilencer"}], "taxonomy_version": 1}, "enriched": {"inputs": [], "kind": "computed", "method": "enrichment_status"}, "function": {"confidence": null, "enriched_at": "2026-08-30T03:12:11.507082+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "79f1af32a8bedc1da1f5d9b9c378764b0beadf40f708f4fd8f6aeace223fe0e7", "fetched_at": "2026-08-28T04:05:51.402662+00:00", "kind": "readme", "missing": false, "url": "https://github.com/netero1010/EDRSilencer"}], "taxonomy_version": 1}, "health_score": {"inputs": ["days_since_push", "days_since_release", "archived"], "kind": "computed", "method": "health_v1"}, "homepage": {"kind": "observed", "observed_at": "2026-08-28T04:05:51.402662+00:00", "source": "github"}, "language": {"kind": "observed", "observed_at": "2026-08-28T04:05:51.402662+00:00", "source": "github"}, "license": {"kind": "observed", "observed_at": "2026-08-28T04:05:51.402662+00:00", "source": "github"}, "license_family": {"inputs": ["license"], "kind": "computed", "method": "license_family"}, "maturity": {"confidence": null, "enriched_at": "2026-08-30T03:12:11.507082+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "79f1af32a8bedc1da1f5d9b9c378764b0beadf40f708f4fd8f6aeace223fe0e7", "fetched_at": "2026-08-28T04:05:51.402662+00:00", "kind": "readme", "missing": false, "url": "https://github.com/netero1010/EDRSilencer"}], "taxonomy_version": 1}, "member_repos": {"kind": "observed", "observed_at": "2026-08-28T04:05:51.402662+00:00", "source": "github"}, "name": {"kind": "observed", "observed_at": "2026-08-28T04:05:51.402662+00:00", "source": "github"}, "platform": {"confidence": null, "enriched_at": "2026-08-30T03:12:11.507082+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "79f1af32a8bedc1da1f5d9b9c378764b0beadf40f708f4fd8f6aeace223fe0e7", "fetched_at": "2026-08-28T04:05:51.402662+00:00", "kind": "readme", "missing": false, "url": "https://github.com/netero1010/EDRSilencer"}], "taxonomy_version": 1}, "pushed_at": {"kind": "observed", "observed_at": "2026-08-28T04:05:51.402662+00:00", "source": "github"}, "repo": {"kind": "observed", "observed_at": "2026-08-28T04:05:51.402662+00:00", "source": "github"}, "stars": {"kind": "observed", "observed_at": "2026-08-28T04:05:51.402662+00:00", "source": "github"}, "tags": {"confidence": null, "enriched_at": "2026-08-30T03:12:11.507082+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "79f1af32a8bedc1da1f5d9b9c378764b0beadf40f708f4fd8f6aeace223fe0e7", "fetched_at": "2026-08-28T04:05:51.402662+00:00", "kind": "readme", "missing": false, "url": "https://github.com/netero1010/EDRSilencer"}], "taxonomy_version": 1}, "topics": {"kind": "observed", "observed_at": "2026-08-28T04:05:51.402662+00:00", "source": "github"}, "urls": {"kind": "observed", "observed_at": "2026-08-28T04:05:51.402662+00:00", "source": "github"}, "use_cases": {"confidence": null, "enriched_at": "2026-08-30T03:12:11.507082+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "79f1af32a8bedc1da1f5d9b9c378764b0beadf40f708f4fd8f6aeace223fe0e7", "fetched_at": "2026-08-28T04:05:51.402662+00:00", "kind": "readme", "missing": false, "url": "https://github.com/netero1010/EDRSilencer"}], "taxonomy_version": 1}, "what_it_is": {"confidence": null, "enriched_at": "2026-08-30T03:12:11.507082+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "79f1af32a8bedc1da1f5d9b9c378764b0beadf40f708f4fd8f6aeace223fe0e7", "fetched_at": "2026-08-28T04:05:51.402662+00:00", "kind": "readme", "missing": false, "url": "https://github.com/netero1010/EDRSilencer"}], "taxonomy_version": 1}, "when_to_avoid": {"confidence": null, "enriched_at": "2026-08-30T03:12:11.507082+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "79f1af32a8bedc1da1f5d9b9c378764b0beadf40f708f4fd8f6aeace223fe0e7", "fetched_at": "2026-08-28T04:05:51.402662+00:00", "kind": "readme", "missing": false, "url": "https://github.com/netero1010/EDRSilencer"}], "taxonomy_version": 1}, "when_to_choose": {"confidence": null, "enriched_at": "2026-08-30T03:12:11.507082+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "79f1af32a8bedc1da1f5d9b9c378764b0beadf40f708f4fd8f6aeace223fe0e7", "fetched_at": "2026-08-28T04:05:51.402662+00:00", "kind": "readme", "missing": false, "url": "https://github.com/netero1010/EDRSilencer"}], "taxonomy_version": 1}}, "score": {"components": {"activity": 0, "longevity": 70, "rhythm": 8}, "computed_at": "2026-09-02T17:46:02.011165+00:00", "flags": [], "formula": "round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)", "inputs": {"age_days": 981, "days_push": 668, "days_rel": 668, "gap_med": null, "n_releases_24m": 1}, "score": 17, "version": 2}, "staleness": {"enrichment_outdated": false, "low_confidence": false, "scrape_days": 9, "stale_scrape": false}}