Hunting and Defeating Evasive Threats
ID: 06bcd374-683e-5e49-afb3-4cc48597fbf4
STIX ID: report--06bcd374-683e-5e49-afb3-4cc48597fbf4
Feed Name: Binary Defense Blog
Threat Score
This report reviews prevalent attacker evasion techniques—crypting/FUD to bypass antivirus, loaders delivered via Office macros that launch trusted processes, DNS tunneling for stealthy C2 and exfiltration, and internal proxying of RDP—and provides practical detection guidance for threat hunters (detailed process/command-line logging, DNS query logging, and Windows event monitoring) to improve detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
