logo

Adversarial Oracles: LLM-Guided EDR Signature Reduction

ID: 3d520a17-d941-572a-a9b3-e1bb31a24d98

STIX ID: report--3d520a17-d941-572a-a9b3-e1bb31a24d98

Feed Name: Security Boulevard

Threat Score
70/100

Date Published: 2026-05-28

Date Updated: 2026-05-29

Author: Michelle Rhodes

...
...

This post explains an automated workflow that leverages large language models and VirusTotal as an oracle to iteratively modify Go-based offensive tools (examples: Goffloader, Sliver) to reduce AV/EDR detections. It describes triage of detection types, hypothesis-driven single-variable rebuilds, creation of 'ghost profiles' to mimic benign Go symbol tables, fixes for YARA-style signature triggers, operational caveats around VirusTotal OPSEC, and an outer Go loader that embeds a WASM-compiled payload as a disguise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.