Table of Contents
Loading contents...
README.md
ThunderStrike EDR
Introduction
I create this project to Learn Edr Internals and Windows kernel Programming.
🚀 Features
It only has one feature right now which is inject a Hook DLL into each process using KAPC.
I will add More Features in the future.
⚠️ Caution
This project is under development, so please use it with caution. It is recommended to run it inside a virtual machine to avoid any risks to your main system.
📝 To-Do
-
Implement a memory scanner.
-
Integrate basic logging and alerting system.
-
Integrate ETW / ETW-TI
📚 Resources
-
Evading EDR Book (By Matt Hand).
-
SensePost – From Windows Drivers to an Almost Fully Working EDR (2024)
-
Experimenting with Protected Processes and Threat-Intelligence
Tool Information
Author
d5fa4lt
Project Added On
July 22, 2025
License
Open Source