logo

Bypassing Cylance: Part 4 – Metasploit Meterpreter & PowerShell Empire Agent

ID: d5934414-3557-5497-bf9a-f833078bb935

STIX ID: report--d5934414-3557-5497-bf9a-f833078bb935

Feed Name: Black Hills Infosec Blog

Threat Score
70/100

Date Published: 2017-03-30

Date Updated: 2026-04-27

Author: BHIS

...
...

This Black Hills InfoSec report documents hands-on testing of Cylance endpoint protection: Metasploit Meterpreter payloads were repeatedly detected and blocked, but renaming the native PowerShell executable allowed a PowerShell Empire agent to execute and establish C2. With default settings the agent was identified after ~3 hours, but after adding jitter and non-default resources the Empire beacon evaded detection for more than 24 hours, illustrating an AV-evasion TTP and the need for defense-in-depth.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.