Ross ROSS = Recommend OSS · open-source software intelligence for agents

tihanyin/PSSW100AVB

A list of useful Powershell scripts with 100% AV bypass (At the time of publication). observed · 2026-08-28

github.com/tihanyin/PSSW100AVB · PowerShell observed · 2026-08-28

Health v2 · maintenance only

70/100

  • Activity 85
  • Release rhythm 35
  • Longevity 100

Flags: no_releases no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 1790
  • days_rel: n/a
  • days_push: 90
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

1405 stars · 214 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

A curated collection of PowerShell scripts demonstrating antivirus evasion techniques, most notably reverse shells that go undetected by AV engines at time of publication. It is aimed at authorized penetration testing, red team operations, adversary simulation, and defensive research on detection evasion, and is updated periodically with fresh undetected variants.

Use cases

  • test whether antivirus engines flag powershell scripts
  • get an undetected reverse shell during an authorized pentest
  • bypass windows defender with a powershell payload
  • evade sandbox and AI-based behavioral analysis in red team exercises
  • study current AV evasion techniques in powershell
  • generate fresh payloads for adversary simulation before vendors flag them
  • train blue teams on what evasion payloads look like

When to choose

  • you run authorized red team or penetration test engagements and need current AV-bypass demonstrations
  • you research or teach antivirus/EDR detection evasion and want real working examples
  • you need a quick undetected PowerShell reverse shell for an approved operation within its undetected window
  • you want to evaluate how quickly vendors flag new evasion techniques

When to avoid

  • you lack explicit authorization for the target environment - these are offensive payloads
  • you need a stable long-term tool - scripts typically get flagged by vendors within days to weeks
  • you want defensive tooling or malware detection - this is offensive research material, not a defense product
  • you need a maintained library with an API or license guarantees - it is a loose collection of scripts with no license file

Facets

cli-tool · maturity active

security penetration-testing security penetration-testing windows windows cross-platform cli powershell av-bypass antivirus-evasion reverse-shell red-team offensive-security sandbox-evasion edr-evasion adversary-simulation malware-analysis security-research curated-list

1 source

Member repositories

RepositoryRoleHealth v2
tihanyin/PSSW100AVBmain70

For agents

markdown · JSON · MCP: product_card(name="tihanyin/PSSW100AVB")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem