Skip to content

Defense Evasion

Malware —and the red team that emulates it in authorized exercises— aims to go unnoticed by antivirus, EDR, and analysts. This card catalogs the evasion families with Red Team / Blue Team parity: which techniques exist and how they work conceptually (to emulate them in an authorized exercise and to recognize them when analyzing a sample), and how they’re detected and mitigated. Evasion in interactive Windows post-exploitation is detailed in win-evasion; here it’s seen from the malware lifecycle view.

Each defensive layer has a blind spot. AV relies on static signatures → break it by changing the signature (obfuscation/packing). The sandbox runs for a limited time in an artificial environment → evade it by detecting that environment or waiting. The EDR observes behavior in user-land → the aim is to reduce its visibility. The adversary’s goal is for the payload to arrive and act without any layer recognizing it; the defender’s, to catch it by what it can’t hide: its effect.

Red Team — evasion families (conceptual)

Section titled “Red Team — evasion families (conceptual)”

Obfuscation and packing of the artifact so it doesn’t match known signatures (see Obfuscation and Packing). Red teams generate unique implants per campaign (“FUD” payloads in the jargon) precisely so the hash and patterns aren’t in AV databases.

The code checks whether it runs in an analysis environment and, if so, doesn’t deploy the real logic:

# signals it looks for (conceptual):
- virtualization artifacts (drivers, device names, VM MACs)
- scarce resources (few cores/RAM), low uptime, no human interaction
- "sleeping" at startup to exhaust the sandbox's analysis time
# also: conditional execution (geofencing by IP/language, only in the target domain)

The EDR observes calls by hooking user-land APIs and receiving events (ETW). The conceptual techniques a red team emulates to reduce that visibility —the same ones you’ll see in win-evasion— include:

AMSI patching neutralize the process's own script scanning in memory
ETW patching blind .NET/PowerShell telemetry
unhooking restore ntdll's original bytes to remove the EDR's hooks
direct/indirect syscalls invoke syscalls bypassing the hooked APIs
process injection run inside a legitimate process (hollowing, module stomping)
BYOVD load a signed vulnerable driver to operate from the kernel

(These techniques are explained in more detail in Defense Evasion (AMSI / AV / EDR). The principle: they all reduce what the EDR sees, not what the code does.)

Living off the Land (LOLBins) and fileless

Section titled “Living off the Land (LOLBins) and fileless”

Instead of its own (detectable) executable, abuse legitimate signed OS binaries, and operate in memory without touching disk:

LOLBins mshta, rundll32, regsvr32, certutil, bitsadmin, wmic, msbuild, powershell
fileless memory injection, registry/WMI scripts -> few disk artifacts
# reference catalog: the LOLBAS project

In authorized exercises, red teams use C2 frameworks with built-in evasion capabilities (malleable profiles, in-memory execution, BOFs): Cobalt Strike (commercial, the standard), Sliver, Mythic, Havoc, Metasploit/Meterpreter. Recognizing their artifacts is also part of blue team (see Command & Control for detecting their traffic).

# detection by BEHAVIOR, not static signature (which evasion breaks)
EDR remote threads, injection, LSASS access, RWX allocations, region patching
AMSI + 4104 scripts captured after deobfuscation (key against fileless/PowerShell)
Sysmon process create (1) with command line, image load (7), CreateRemoteThread (8)
Sigma rules on anomalous command lines (LOLBins), -enc, downloads
ETW-TI kernel telemetry that resists some user-land tampering
# hunt what evasion CAN'T hide: the effect (network/C2, encryption, persistence)

Sysmon (1/7/8/10/25), PowerShell auditing (Script Block Logging 4104), the ETW Threat Intelligence provider, and SIEM correlation. Memory detection (YARA over processes, see YARA Rules) catches what evades the disk.

  • EDR with behavior detection and anti-tamper (resistant to visibility reduction).
  • Application allowlisting (WDAC/AppLocker): cuts LOLBins and unauthorized executables.
  • Constrained Language Mode + Script Block Logging + AMSI; forwarded, protected logging.
  • Driver Blocklist (against BYOVD), HVCI/Credential Guard; reduce unnecessary interpreters/binaries.
  • Assume evasion: robust detection is multi-layer (endpoint + network + memory), not one signature.
  • AMSI/ETW patching, unhooking, and BYOVD are standard red-team and APT/ransomware TTPs (MITRE T1562.001 Impair Defenses, T1055 Process Injection, T1620 Reflective Loading).
  • BYOVD: campaigns by BlackByte, LockBit, Scattered Spider with signed vulnerable drivers (e.g. CVE-2021-21551 Dell dbutil, RTCore64).
  • Cobalt Strike leaks and the maturity of open-source frameworks (Sliver/Havoc) have spread these capabilities.
  • Does the sample/implant evade static signatures? (unique hash, packing)
  • Does it detect VM/sandbox or use geofencing? (“does nothing”)
  • EDR-evasion techniques present (AMSI/ETW/unhooking/syscalls)
  • LOLBins and fileless activity (memory, WMI, registry)
  • Identify the C2 framework if applicable (artifacts, see Command & Control)
  • Blue: does behavior detection (EDR/Sigma) catch it?
  • Blue: AMSI/Script Block Logging and in-memory YARA
  • Map to MITRE ATT&CK (TA0005 Defense Evasion)