Defense Evasion
Malware —and the red team that emulates it in authorized exercises— aims to go unnoticed by antivirus, EDR, and analysts. This card catalogs the evasion families with Red Team / Blue Team parity: which techniques exist and how they work conceptually (to emulate them in an authorized exercise and to recognize them when analyzing a sample), and how they’re detected and mitigated. Evasion in interactive Windows post-exploitation is detailed in win-evasion; here it’s seen from the malware lifecycle view.
Threat model
Section titled “Threat model”Each defensive layer has a blind spot. AV relies on static signatures → break it by changing the signature (obfuscation/packing). The sandbox runs for a limited time in an artificial environment → evade it by detecting that environment or waiting. The EDR observes behavior in user-land → the aim is to reduce its visibility. The adversary’s goal is for the payload to arrive and act without any layer recognizing it; the defender’s, to catch it by what it can’t hide: its effect.
Red Team — evasion families (conceptual)
Section titled “Red Team — evasion families (conceptual)”Signature evasion (static)
Section titled “Signature evasion (static)”Obfuscation and packing of the artifact so it doesn’t match known signatures (see Obfuscation and Packing). Red teams generate unique implants per campaign (“FUD” payloads in the jargon) precisely so the hash and patterns aren’t in AV databases.
Sandbox / analysis-environment evasion
Section titled “Sandbox / analysis-environment evasion”The code checks whether it runs in an analysis environment and, if so, doesn’t deploy the real logic:
# signals it looks for (conceptual):- virtualization artifacts (drivers, device names, VM MACs)- scarce resources (few cores/RAM), low uptime, no human interaction- "sleeping" at startup to exhaust the sandbox's analysis time# also: conditional execution (geofencing by IP/language, only in the target domain)EDR evasion (user-land)
Section titled “EDR evasion (user-land)”The EDR observes calls by hooking user-land APIs and receiving events (ETW). The conceptual techniques a red team emulates to reduce that visibility —the same ones you’ll see in win-evasion— include:
AMSI patching neutralize the process's own script scanning in memoryETW patching blind .NET/PowerShell telemetryunhooking restore ntdll's original bytes to remove the EDR's hooksdirect/indirect syscalls invoke syscalls bypassing the hooked APIsprocess injection run inside a legitimate process (hollowing, module stomping)BYOVD load a signed vulnerable driver to operate from the kernel(These techniques are explained in more detail in Defense Evasion (AMSI / AV / EDR). The principle: they all reduce what the EDR sees, not what the code does.)
Living off the Land (LOLBins) and fileless
Section titled “Living off the Land (LOLBins) and fileless”Instead of its own (detectable) executable, abuse legitimate signed OS binaries, and operate in memory without touching disk:
LOLBins mshta, rundll32, regsvr32, certutil, bitsadmin, wmic, msbuild, powershellfileless memory injection, registry/WMI scripts -> few disk artifacts# reference catalog: the LOLBAS projectFrameworks the red team uses (reference)
Section titled “Frameworks the red team uses (reference)”In authorized exercises, red teams use C2 frameworks with built-in evasion capabilities (malleable profiles, in-memory execution, BOFs): Cobalt Strike (commercial, the standard), Sliver, Mythic, Havoc, Metasploit/Meterpreter. Recognizing their artifacts is also part of blue team (see Command & Control for detecting their traffic).
Blue Team — detection
Section titled “Blue Team — detection”# detection by BEHAVIOR, not static signature (which evasion breaks)EDR remote threads, injection, LSASS access, RWX allocations, region patchingAMSI + 4104 scripts captured after deobfuscation (key against fileless/PowerShell)Sysmon process create (1) with command line, image load (7), CreateRemoteThread (8)Sigma rules on anomalous command lines (LOLBins), -enc, downloadsETW-TI kernel telemetry that resists some user-land tampering# hunt what evasion CAN'T hide: the effect (network/C2, encryption, persistence)Telemetry
Section titled “Telemetry”Sysmon (1/7/8/10/25), PowerShell auditing (Script Block Logging 4104), the ETW Threat Intelligence provider, and SIEM correlation. Memory detection (YARA over processes, see YARA Rules) catches what evades the disk.
Hardening
Section titled “Hardening”- EDR with behavior detection and anti-tamper (resistant to visibility reduction).
- Application allowlisting (WDAC/AppLocker): cuts LOLBins and unauthorized executables.
- Constrained Language Mode + Script Block Logging + AMSI; forwarded, protected logging.
- Driver Blocklist (against BYOVD), HVCI/Credential Guard; reduce unnecessary interpreters/binaries.
- Assume evasion: robust detection is multi-layer (endpoint + network + memory), not one signature.
CVEs and real-world cases
Section titled “CVEs and real-world cases”- AMSI/ETW patching, unhooking, and BYOVD are standard red-team and APT/ransomware TTPs (MITRE T1562.001 Impair Defenses, T1055 Process Injection, T1620 Reflective Loading).
- BYOVD: campaigns by BlackByte, LockBit, Scattered Spider with signed vulnerable drivers (e.g. CVE-2021-21551 Dell dbutil, RTCore64).
- Cobalt Strike leaks and the maturity of open-source frameworks (Sliver/Havoc) have spread these capabilities.
Testing checklist
Section titled “Testing checklist”- Does the sample/implant evade static signatures? (unique hash, packing)
- Does it detect VM/sandbox or use geofencing? (“does nothing”)
- EDR-evasion techniques present (AMSI/ETW/unhooking/syscalls)
- LOLBins and fileless activity (memory, WMI, registry)
- Identify the C2 framework if applicable (artifacts, see Command & Control)
- Blue: does behavior detection (EDR/Sigma) catch it?
- Blue: AMSI/Script Block Logging and in-memory YARA
- Map to MITRE ATT&CK (TA0005 Defense Evasion)