Evasion techniques are methods attackers use to bypass or circumvent security controls such as firewalls, intrusion detection systems, and antivirus software.
Evasion techniques are methods used by attackers and penetration testers to bypass security controls without triggering alerts. These techniques target firewalls, IDS/IPS, antivirus, EDR, and web application firewalls. Understanding evasion is critical for both offensive testing and defensive tuning because security tools are only effective against threats they can detect.
Network-level evasion includes packet fragmentation, protocol-level ambiguity exploitation, TTL manipulation, encrypted tunneling through allowed ports, and DNS-based exfiltration. Attackers also use slow-rate scanning to avoid threshold-based detection and IPv6 tunneling to bypass IPv4-only monitoring infrastructure. These techniques exploit gaps between how security tools and endpoints interpret traffic.
Attackers evade EDR through API unhooking, direct system calls that bypass user-mode hooks, process hollowing, DLL sideloading into trusted applications, and timestomping. Disabling or blinding EDR agents through kernel-level access or exploiting exclusion paths are also common. Advanced adversaries chain multiple techniques to maintain stealth throughout an operation.
Living-off-the-land involves using legitimate system tools like PowerShell, WMI, certutil, and mshta to execute malicious actions. Because these binaries are trusted by the operating system and security tools, their use generates fewer alerts. This technique is effective because defenders cannot simply block built-in system utilities without disrupting normal operations.
Penetration testers use evasion techniques to validate whether security controls detect real-world attack patterns. Testing is conducted within defined scope and rules of engagement. Results help organizations identify detection gaps, tune alert thresholds, and improve security operations. Responsible evasion testing strengthens defenses rather than undermining them.
Polymorphic malware changes its code signature with each iteration while maintaining functionality, using encryption or encoding routines that vary per infection. Metamorphic malware goes further by completely rewriting its own code structure. Both techniques defeat signature-based detection, requiring behavioral analysis and machine learning for effective identification.
Organizations should deploy behavioral analytics rather than relying solely on signatures, implement network traffic analysis for encrypted channel monitoring, use application whitelisting, and conduct regular red team exercises. Defense-in-depth ensures that evasion of one control is caught by another layer. Continuous tuning based on threat intelligence keeps defenses current.
Obfuscation transforms malicious code to make it unrecognizable to static analysis tools while preserving functionality. Techniques include string encoding, control flow flattening, dead code insertion, and variable renaming. Obfuscation is used in both compiled payloads and scripts, making manual and automated analysis significantly more time-consuming for defenders.