A practical walkthrough of seven real-world defense evasion techniques observed by Huntress, covering: disabling/excluding AV via PowerShell (T1562.001), killing EDR processes with Backstab, obfuscated PowerShell scripts and AsyncRAT delivery (T1027), executables hidden inside LNK shortcut files (T1036), AMSI/ETW bypass techniques, social engineering via fake QuickBooks popups (T1204), and reflective loading into trusted binaries like CasPol.exe (T1620). Each case includes MITRE ATT&CK references and brief detection notes, with emphasis on how attackers exploit both technical gaps and human behavior.

12m read timeFrom huntress.com
Post cover image
Table of contents
Case One: Impairing DefensesCase Two: Impairing Defenses by Turning Things OffCase Three: Obfuscate, FrustrateCase Four: LNK to EXECase Five: AMSI BypassCase Six: Layer Eight AttackCase Seven: Reflective LoadingA Stress Indeed