Defense Evasion

  • most AV have 2 core strategies for detecting malicious activity
    • signatures that target known or static portions of a payload
    • behavioral heuristics to detect post-exploitation actions
  • We need to know how t modify our payloads and post-exploitation behavior to evade these detections