Evasion¶
Avoiding detection by antivirus, EDR, and network monitoring during an engagement.
Why It Matters¶
A realistic assessment tests detection as well as prevention. Understanding how defenses see an action, and how real attackers avoid being seen, is what makes an engagement representative of a genuine threat rather than a noisy scan the blue team catches immediately.
Reference¶
What Defenses Watch¶
| Layer | Signals |
|---|---|
| Endpoint (AV/EDR) | Known tool signatures, suspicious process trees, LSASS access, script content |
| Network | Beaconing patterns, connections to new infrastructure, large transfers |
| Identity | Anomalous logons, lateral movement, privilege changes |
| Logging | Event log clearing, audit policy changes |
General Principles¶
- Live off the land: prefer built-in binaries (LOLBAS) and native protocols over dropped tools
- Minimize footprint: fewer actions, on fewer hosts, at a measured pace
- Blend in: use expected ports, times, and accounts where possible
- Avoid known-bad tooling on monitored hosts; signatured tools like Mimikatz are flagged on sight
- Clean up: track artifacts created so they can be removed and reported
Evasion is scoped, not unlimited
Evasion techniques are used within the rules of engagement to test detection, not to cause harm or hide activity from the client. Red team work is documented in full; the goal is to measure what defenses catch, and report what they miss.
How I Use It¶
I decide up front how quiet the engagement needs to be: an overt test can be noisy, while a red team exercise against a mature SOC is as much about evasion as access. On monitored networks I favor built-in tooling and native protocols, keep actions minimal, and record everything I do so the report can compare what I did against what the blue team detected.