Red-Teaming
Defense Evasion
MITRE ATT&CK™ Defense Evasion - Tactic TA0005
Theory
Defense Evasion consists of techniques that adversaries use to avoid detection throughout their compromise. Techniques used for defense evasion include uninstalling/disabling security software or obfuscating/encrypting data and scripts. Adversaries also leverage and abuse trusted processes to hide and masquerade their malware. Other tactics’ techniques are cross-listed here when those techniques include the added benefit of subverting defenses.

Resources
AppLocker BypassETW evasionMITRE ATT&CK™ Impair Defenses: Disable or Modify Tools - Technique T1562.002Kill Windows DefenderWIPMark-of-the-Web (MotW) Bypass>-PowerShell Constrained Language Mode (CLM) BypassWIPSandbox EvasionWIPMITRE ATT&CK™ Virtualization/Sandbox Evasion- Technique T1497Signature EvasionAMSI BypassMITRE ATT&CK™ Impair Defenses: Disable or Modify Tools - Technique T1562.001Endpoint Detection Respons (EDR) BypassLiving Off The LandObfuscationUAC BypassMITRE ATT&CK™ Impair Defenses: Disable or Modify Tools - Technique T1562.001Virtualization-based security (VBS) BypassWIP