Back to browse
GitHub Repository

ShadowStrike A Windows EDR Platform

26 starsC++

Open-Source ShadowStrike Phantom EDR/XDR Platform Progress-Post

by Soocile·Apr 17, 2026·1 point·2 comments

AI Analysis

●●SolidWizardryBold Bet

Custom kernel driver with 1.5M+ lines of code competing against CrowdStrike and SentinelOne.

Strengths
  • Kernel-mode PhantomSensor.sys passes Driver Verifier with ETW tracing active
  • Full-system emulation engine for behavioral analysis without sandboxing
  • 1.5M+ lines of C/C++/ASM shows serious engineering commitment
Weaknesses
  • Alpha stage with beta target in early 2027 — years from production use
  • Windows-only in a category where cross-platform is table stakes
Category
Target Audience

Security engineers, Windows system administrators, open-source security advocates

Similar To

CrowdStrike Falcon · SentinelOne · Microsoft Defender for Endpoint

Post Description

ShadowStrike Phantom is a Open-Source Endpoint Protection Platform at Github.

Mainly we will have 3 product tiers | |->ShadowStrike Phantom Shared Modules(PhantomCore + PhantomEmulator/disassembler + PhantomCortex AI/ML models + PhantomSensor(kernel driver)) |+ |->Phantom Home(For mostly home users - will have a local UI to control the Antivirus and will have some extra stuff like privacy - gamemode etc. For home-users) | |->Phantom EDR(For the Endpoints - will have the local web dashboard For Community Enterprise-users + Endpoint-specific additional protections + forensics) | |->Phantom XDR(Extended detection for endpoints - will include SIEM Integrations etc. Every related-stuff will be added to this product)

Community/EDR-XDR-Home products will be able to work locally at the Host Machine. And we are planning to do Phantom Pro - Phantom Enterprise products that will include cloud-based systems - Global Threat Intelligence - Online Web Threat Intel Dashboards For companies etc. stuff.[Of course, we need capital to do these things, so they are part of our long-term plan.]

Currently We are mostly extracting the Attack surface-map of the ShadowStrike Phantom and Fuzzing it with our harnesses - Integration/Unit tests - Coverity/PVS-Studio scans - Working with the Product Splits and their own additional protection features - Bugfixes - Security Vulnerabilities - Kernel BSODs. Pretty much everything...

If you are interested in the Open-Source Endpoint Detection and Response/Extended detection and Response/Antivirus Systems and Kernel Stuff and lots of C/C++:

Github : https://github.com/ShadowStrike-Labs/ShadowStrike

Similar Projects

Security●●Solid

Rust EDR Agent for Linux with eBPF and macOS

Rust EDR with eBPF on Linux competes against CrowdStrike and Wazuh.

WizardryNiche Gem
irqlevel
102mo ago