Impair Defenses
Defense evasion encompasses techniques by which an attacker conceals their activity from security tools, analysts, and automated detection systems. The goal is to remain undetected for as long as possible in the compromised environment.
Term
description · examples · notesDefense evasion encompasses techniques by which an attacker conceals their activity from security tools, analysts, and automated detection systems. The goal is to remain undetected for as long as possible in the compromised environment.
Description
Methods include disabling security software, clearing activity logs, disguising malicious processes with legitimate names, using encryption, and exploiting legitimate system tools.
Examples
- Disabling antivirus software on a compromised system
- Clearing system logs that record attacker activity
- Executing malicious code through legitimate system tools
- Encrypting command server communication to resemble normal traffic
Notes
- Centralized log collection outside the compromised system makes it harder for the attacker to erase traces.
Mentioned in the news
- 20. MAR 2026. ESET: EDR killer alati su postali predvidiva faza modernih ransomware upada →
- 11. MAR 2026. BlackSanta malver koristi HR procese zapošljavanja da zaobiđe EDR zaštitu →
- 11. MAR 2026. BlackSanta malver gasi EDR i antivirus pre krađe podataka →
- 18. FEB 2026. Napadači koriste DKIM replay napade za zaobilaženje bezbednosnih filtera →
- 19. JUN 2026. Ransomver banda Gentlemen svoje saradnike snabdeva sa alatima za gašenje naprednih mehanizama zaštite →
- 20. MAJ 2026. VoidStealer zaobilazi Chrome zaštitu i krade podatke iz browsera →
- 7. MAJ 2026. Remus malware zaobilazi zaštitu u Chromium browserima →
- 20. APR 2026. Ransom note ne otkriva kako zaista radi ransomware industrija →
- 19. APR 2026. Payouts King koristi QEMU virtuelne mašine da zaobiđe endpoint zaštitu →
- 2. APR 2026. Zašto napadači sve češće zloupotrebljavaju legitimne alate u okruženju? →
- 2. APR 2026. CrySome RAT dobio HVNC i AV killer module →
- 29. MAR 2026. VoidLink rootkit koristi eBPF i kernel module za prikriven rad na Linuxu →
- 28. MAR 2026. Red Menshen koristi BPFDoor za prikriveno prisustvo u telekom mrežama →
- 28. MAR 2026. Kako napadači uz AI oponašaju legitimno ponašanje i zašto je NDR važan →
- 23. MAR 2026. LockBit 5.0 zahvata celu infrastrukturu →
- 24. FEB 2026. Napadači zloupotrebljavaju Windows alate za upravljanje za prikriveni pristup →
- 14. FEB 2026. Spiderman fišing kit cilja Microsoft 365 naloge →
- 13. FEB 2026. Zlonamerna virtuelna mašina cilja VMware vSphere okruženja →
- 12. FEB 2026. Reynolds ransomver koristi BYOVD tehniku za zaobilaženje zaštite →
Threats
used by 8Threats that use it. Select one to open its page.
Defenses
countered by 7How it is countered. Select one to open its page.