Defense Evasion 18 articles
More in Techniques, Tactics & Procedures (TTPs):
Command & Control 17
Defense Evasion 18
Execution 17
Exfiltration 15
Initial Access 22
Lateral Movement 16
Persistence 18
Privilege Escalation 16
SaaS Platforms 18
01
Abuse of Trusted Cloud Services
Overview Abuse of trusted cloud services involves adversaries leveraging legitimate cloud platforms and services to facilitate various stages of an attack. This technique enables attackers to blend malicious activity with…
02
Bypassing Application Control
Overview Bypassing application control is a technique used by adversaries to circumvent security mechanisms that restrict or block the execution of unauthorized software. This technique plays a critical role in…
03
Disabling or Modifying Security Tools
Overview Disabling or modifying security tools is a technique used by adversaries to undermine defensive mechanisms within a target environment. This approach facilitates stealth and persistence by reducing the likelihood…
04
Encoded Command Execution
Overview Encoded Command Execution is a technique used by adversaries to run commands or scripts in an encoded format to evade detection and bypass security controls. This technique is commonly…
05
Encrypted Payload Delivery
Overview Encrypted Payload Delivery is a technique used by adversaries to conceal malicious payloads within encrypted or obfuscated data streams during transmission. This method helps attackers evade detection mechanisms by…
06
Fileless Malware Techniques
Overview Fileless malware techniques involve executing malicious activities without writing files to disk, leveraging legitimate system tools and memory-resident code. These techniques are used throughout various stages of the attack…
07
Kernel Hooking Techniques
Overview Kernel hooking techniques involve intercepting or modifying kernel-level functions to alter system behavior. Adversaries use these techniques to gain stealth, persistence, or elevated privileges during various stages of an…
08
Living-off-the-Land Evasion Techniques
Overview Living-off-the-Land (LotL) evasion techniques involve adversaries leveraging legitimate system tools, utilities, and features to carry out malicious activities while minimizing detection. These techniques play a critical role in the…
09
Log Clearing and Log Tampering
Overview Log clearing and log tampering are techniques used by adversaries to remove or alter evidence of their activities within system and security logs. These actions primarily serve to evade…
10
Masquerading Files and Processes
Overview Masquerading files and processes is a technique where adversaries disguise malicious files or processes to appear as legitimate system or application components. This method is used to evade detection…
11
Obfuscated Files and Information
Overview Obfuscated Files and Information is a technique used by adversaries to conceal malicious code, data, or communication within files or information streams. It plays a critical role in the…
12
Process Injection Techniques
Overview Process injection techniques involve an adversary inserting malicious code into the address space of another process to execute code stealthily. This approach enables attackers to evade detection, maintain persistence,…
13
Reflective DLL Injection
Overview Reflective DLL Injection is a technique used by adversaries to inject a Dynamic Link Library (DLL) into the address space of a target process without using the Windows loader.…
14
Rootkit Deployment
Overview Rootkit deployment is a technique used by adversaries to maintain stealthy and persistent control over a compromised system by installing software that hides its presence and activities. It plays…
15
Signed Binary Abuse for Evasion
Overview Signed Binary Abuse for Evasion is a technique where adversaries leverage digitally signed legitimate binaries to execute malicious code while bypassing security controls. This approach is used throughout various…
16
Tampering with Endpoint Protection
Overview Tampering with endpoint protection involves adversaries manipulating or disabling security controls on endpoint devices to evade detection and maintain persistence. This technique is commonly employed during various stages of…
17
Time-Based Evasion Techniques
Overview Time-Based Evasion Techniques involve adversaries manipulating or exploiting timing mechanisms to avoid detection and analysis during cyber attacks. These techniques are employed across various stages of the attack lifecycle…
18
Virtualization and Sandbox Evasion
Overview Virtualization and sandbox evasion techniques are employed by adversaries to detect and circumvent environments designed for malware analysis and automated security inspection. These techniques play a critical role in…