This repository documents EDR evasion techniques and LSASS credential dumping (MITRE ATT&CK T1003.001) for educational and authorized security assessment purposes.
This material is intended for:
- Licensed penetration testers operating under a signed Rules of Engagement (RoE)
- Red team operators conducting authorized adversary simulations
- Defensive security teams (blue/purple teams) studying attacker TTPs to improve detection
Using these techniques against systems without explicit written authorization is illegal under computer fraud laws including the CFAA (US), Computer Misuse Act (UK), and TCK Articles 243-244 (Turkey). The author assumes no liability for unauthorized use.
I cloned an EDR evasion project that incorporates dumping LSASS via ProcMon.