Ross ROSS = Recommend OSS · open-source software intelligence for agents

optiv/ScareCrow

ScareCrow - Payload creation framework designed around EDR bypass. observed · 2026-08-28

github.com/optiv/ScareCrow · Go · archived observed · 2026-08-28

Health v2 · maintenance only

10/100

  • Activity 0
  • Release rhythm 8
  • Longevity 100

Flags: archived no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 2047
  • days_rel: n/a
  • days_push: 1111
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

2890 stars · 529 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

ScareCrow is a Go-based payload creation framework designed to bypass EDR (Endpoint Detection and Response) and application whitelisting controls. It generates sideloading loaders for Windows that remove EDR hooks from system DLLs in memory using techniques like DLL unhooking and indirect syscalls.

Use cases

  • generate payloads that bypass EDR detection
  • create sideloading loaders for legitimate Windows processes
  • bypass application whitelisting controls
  • unhook EDR hooks from system DLLs in memory
  • test endpoint detection coverage with evasion techniques
  • encrypt shellcode with multiple encryption methods

When to choose

  • you are a red teamer or penetration tester testing EDR effectiveness
  • you need to generate Windows loaders that sideload into legitimate processes
  • you want to evaluate whether your EDR can detect DLL unhooking and indirect syscall techniques

When to avoid

  • you want active development or support - this repository is archived and moved to Tylous/ScareCrow
  • you need a defensive or detection tool rather than an offensive one
  • you are not working on Windows targets
  • you cannot accept the project having no license

Facets

cli-tool · maturity abandoned

security penetration-testing security penetration-testing developer-tools windows go cli edr-bypass payload-generation evasion red-team shellcode-loader archived

1 source

Member repositories

RepositoryRoleHealth v2
optiv/ScareCrowmain10

For agents

markdown · JSON · MCP: product_card(name="optiv/ScareCrow")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem