logo

The Mechanics of Defense Evasion | Huntress

ID: bf6d6222-e475-58fb-a402-515d40131297

STIX ID: report--bf6d6222-e475-58fb-a402-515d40131297

Feed Name: Huntress Blog

Threat Score
65/100

Date Published: 2024-06-24

Date Updated: 2026-04-28

...
...

A Huntress blog post surveys seven real-world defense-evasion cases—manipulating AV exclusions and settings, uninstalling or killing security agents, highly obfuscated PowerShell (including AMSI evasion and AsyncRAT), embedding executables in LNK shortcuts, social-engineering user prompts, and reflective loading/process injection—illustrating how attackers evade detection, with examples, small IOCs (e.g., new50.noip.me), and notes for defender detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.