{"adoption": {"forks": 193, "observed_at": "2026-08-28T04:04:50.290462+00:00", "stars": 1476}, "canonical_url": "https://ross.abutalabs.com/products/optiv-freeze", "card": {"archived": true, "artifact_type": "cli-tool", "description": "Freeze is a payload toolkit for bypassing EDRs using suspended processes, direct syscalls, and alternative execution methods", "domain": ["security", "penetration-testing", "windows"], "enriched": true, "function": ["security", "penetration-testing"], "health_score": 10, "homepage": null, "language": "Go", "license": "MIT", "license_family": "permissive", "maturity": "maintenance", "member_repos": ["optiv/Freeze"], "name": "optiv/Freeze", "platform": ["windows", "cli", "go"], "pushed_at": "2023-08-18T17:25:07+00:00", "repo": "optiv/Freeze", "stars": 1476, "tags": ["edr-bypass", "shellcode-loader", "red-team", "offensive-security", "direct-syscalls", "suspended-processes"], "topics": [], "urls": [], "use_cases": ["bypass EDR to execute shellcode on Windows", "generate stealthy shellcode loaders for red team engagements", "remove userland EDR hooks from a payload", "test endpoint detection controls against evasion techniques", "create payloads using suspended process and direct syscall techniques"], "what_it_is": "Freeze is a Go-based payload creation toolkit that generates Windows shellcode loaders designed to bypass EDR security controls. It uses suspended processes, direct syscalls, and ASLR-based techniques to remove userland EDR hooks and execute shellcode stealthily.", "when_to_avoid": ["you need a maintained tool - the original repo is archived and development moved to Tylous/Freeze", "you are not working on authorized offensive security or defensive testing", "you need cross-platform payload generation beyond Windows"], "when_to_choose": ["you are a red teamer or penetration tester needing an EDR evasion payload generator", "you want to test whether your EDR detects suspended-process and direct-syscall shellcode execution", "you need a quick CLI tool to wrap shellcode in an evasive Windows loader"]}, "data_as_of": "2026-08-30T08:39:29.467469+00:00", "members": [{"path": "/products/optiv-freeze", "repo": "optiv/Freeze", "role": "main", "score": 10}], "provenance": {"archived": {"kind": "observed", "observed_at": "2026-08-28T04:04:50.290462+00:00", "source": "github"}, "artifact_type": {"confidence": null, "enriched_at": "2026-08-30T04:34:28.530498+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "32a652033400a28181a2ca3c882b128cbf24a255a7b61b69fb6547520e764cb9", "fetched_at": "2026-08-28T04:04:50.290462+00:00", "kind": "readme", "missing": false, "url": "https://github.com/optiv/Freeze"}], "taxonomy_version": 1}, "description": {"kind": "observed", "observed_at": "2026-08-28T04:04:50.290462+00:00", "source": "github"}, "domain": {"confidence": null, "enriched_at": "2026-08-30T04:34:28.530498+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "32a652033400a28181a2ca3c882b128cbf24a255a7b61b69fb6547520e764cb9", "fetched_at": "2026-08-28T04:04:50.290462+00:00", "kind": "readme", "missing": false, "url": "https://github.com/optiv/Freeze"}], "taxonomy_version": 1}, "enriched": {"inputs": [], "kind": "computed", "method": "enrichment_status"}, "function": {"confidence": null, "enriched_at": "2026-08-30T04:34:28.530498+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "32a652033400a28181a2ca3c882b128cbf24a255a7b61b69fb6547520e764cb9", "fetched_at": "2026-08-28T04:04:50.290462+00:00", "kind": "readme", "missing": false, "url": "https://github.com/optiv/Freeze"}], "taxonomy_version": 1}, "health_score": {"inputs": ["days_since_push", "days_since_release", "archived"], "kind": "computed", "method": "health_v1"}, "homepage": {"kind": "observed", "observed_at": "2026-08-28T04:04:50.290462+00:00", "source": "github"}, "language": {"kind": "observed", "observed_at": "2026-08-28T04:04:50.290462+00:00", "source": "github"}, "license": {"kind": "observed", "observed_at": "2026-08-28T04:04:50.290462+00:00", "source": "github"}, "license_family": {"inputs": ["license"], "kind": "computed", "method": "license_family"}, "maturity": {"confidence": null, "enriched_at": "2026-08-30T04:34:28.530498+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "32a652033400a28181a2ca3c882b128cbf24a255a7b61b69fb6547520e764cb9", "fetched_at": "2026-08-28T04:04:50.290462+00:00", "kind": "readme", "missing": false, "url": "https://github.com/optiv/Freeze"}], "taxonomy_version": 1}, "member_repos": {"kind": "observed", "observed_at": "2026-08-28T04:04:50.290462+00:00", "source": "github"}, "name": {"kind": "observed", "observed_at": "2026-08-28T04:04:50.290462+00:00", "source": "github"}, "platform": {"confidence": null, "enriched_at": "2026-08-30T04:34:28.530498+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "32a652033400a28181a2ca3c882b128cbf24a255a7b61b69fb6547520e764cb9", "fetched_at": "2026-08-28T04:04:50.290462+00:00", "kind": "readme", "missing": false, "url": "https://github.com/optiv/Freeze"}], "taxonomy_version": 1}, "pushed_at": {"kind": "observed", "observed_at": "2026-08-28T04:04:50.290462+00:00", "source": "github"}, "repo": {"kind": "observed", "observed_at": "2026-08-28T04:04:50.290462+00:00", "source": "github"}, "stars": {"kind": "observed", "observed_at": "2026-08-28T04:04:50.290462+00:00", "source": "github"}, "tags": {"confidence": null, "enriched_at": "2026-08-30T04:34:28.530498+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "32a652033400a28181a2ca3c882b128cbf24a255a7b61b69fb6547520e764cb9", "fetched_at": "2026-08-28T04:04:50.290462+00:00", "kind": "readme", "missing": false, "url": "https://github.com/optiv/Freeze"}], "taxonomy_version": 1}, "topics": {"kind": "observed", "observed_at": "2026-08-28T04:04:50.290462+00:00", "source": "github"}, "urls": {"kind": "observed", "observed_at": "2026-08-28T04:04:50.290462+00:00", "source": "github"}, "use_cases": {"confidence": null, "enriched_at": "2026-08-30T04:34:28.530498+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "32a652033400a28181a2ca3c882b128cbf24a255a7b61b69fb6547520e764cb9", "fetched_at": "2026-08-28T04:04:50.290462+00:00", "kind": "readme", "missing": false, "url": "https://github.com/optiv/Freeze"}], "taxonomy_version": 1}, "what_it_is": {"confidence": null, "enriched_at": "2026-08-30T04:34:28.530498+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "32a652033400a28181a2ca3c882b128cbf24a255a7b61b69fb6547520e764cb9", "fetched_at": "2026-08-28T04:04:50.290462+00:00", "kind": "readme", "missing": false, "url": "https://github.com/optiv/Freeze"}], "taxonomy_version": 1}, "when_to_avoid": {"confidence": null, "enriched_at": "2026-08-30T04:34:28.530498+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "32a652033400a28181a2ca3c882b128cbf24a255a7b61b69fb6547520e764cb9", "fetched_at": "2026-08-28T04:04:50.290462+00:00", "kind": "readme", "missing": false, "url": "https://github.com/optiv/Freeze"}], "taxonomy_version": 1}, "when_to_choose": {"confidence": null, "enriched_at": "2026-08-30T04:34:28.530498+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "32a652033400a28181a2ca3c882b128cbf24a255a7b61b69fb6547520e764cb9", "fetched_at": "2026-08-28T04:04:50.290462+00:00", "kind": "readme", "missing": false, "url": "https://github.com/optiv/Freeze"}], "taxonomy_version": 1}}, "score": {"components": {"activity": 0, "longevity": 100, "rhythm": 8}, "computed_at": "2026-09-02T17:46:02.011165+00:00", "flags": ["archived"], "formula": "round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)", "inputs": {"age_days": 1442, "days_push": 1111, "days_rel": null, "gap_med": null, "n_releases_24m": 0}, "score": 10, "version": 2}, "staleness": {"enrichment_outdated": false, "low_confidence": false, "scrape_days": 9, "stale_scrape": false}}