logo

Modifying Metasploit x64 template for AV evasion

ID: 36e2a63a-9732-5a27-b223-744c2ad79b47

STIX ID: report--36e2a63a-9732-5a27-b223-744c2ad79b47

Feed Name: Black Hills Infosec Blog

Threat Score
55/100

Date Published: 2015-10-21

Date Updated: 2026-04-27

Author: BHIS

...
...

This blog post describes experiments modifying Metasploit's 64-bit PE template to evade Avast antivirus: the default template is detected, but simple assembly changes (such as increasing the payload buffer) caused Avast to miss the payloads and allowed successful remote shell execution. The author concludes that some AV engines match template assembly rather than payload shellcode and plans to repeat tests across other AV products.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.