Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
edrEvasionWorkshop — Workshop materials for “Step-by-Step Malware Development: Evading EDR from Loaders to the Kernel” presented at DEF CON 34 and BSidesLV 2026. Covers malware development, EDR Architecture, EDR evasion, C2 customization, and kernel-level techniques. | Kitploit
Tools/GitHubGitHub/tyeurada/edrevasionworkshop
Defensive ToolsExploitationPost-ExploitationMalware AnalysisPenetration TestingLearning & EducationRed TeamingPayload Development

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
GitHub
tyeurada/edrevasionworkshop

edrEvasionWorkshop

Workshop materials for “Step-by-Step Malware Development: Evading EDR from Loaders to the Kernel” presented at DEF CON 34 and BSidesLV 2026. Covers malware development, EDR Architecture, EDR evasion, C2 customization, and kernel-level techniques.

View Repository
31551222 days agoReviewed by Kitploit
Share

edrEvasionWorkshop

Workshop materials for “Step-by-Step Malware Development: Evading EDR from Loaders to the Kernel”, presented at DEF CON 34 and BSidesLV 2026.

This workshop explores custom malware development, EDR Architecture & Evasion, C2 customization, and kernel-level techniques using Elastic Defend as the target EDR.

Step-by-Step Malware Development: Evading EDR from Loaders to the Kernel

Workshop materials from DEF CON 34 and BSidesLV 2026.

The materials cover topics including:

  • EDR Architecture
  • APC Injection
  • Fiber
  • Module Stomping
  • Call Stack Spoofing
  • Indirect Syscalls
  • C2 Customization with Havoc
  • Kernel-Level Attacks

The workshop focuses on understanding how EDR detects malicious behavior and how attackers can modify their techniques to evade detection.

Notes

The Reference directory contains Markdown versions of the workshop materials. These files are provided for reference only and have not been thoroughly reviewed or updated.

During the actual workshops, we used slide-based presentation materials.

The source code used in the workshops was shared with workshop participants. I may make the source code publicly available if there is sufficient interest.

Disclaimer

The techniques and concepts presented in these materials are intended for educational and security research purposes only.

Please do not use these techniques for malicious or unauthorized activities.

We hope these materials help you better understand EDR detection and evasion techniques and, ultimately, improve your security and build stronger defenses.

Download Tool