View Single Post
  #4  
Old 05-14-2018, 23:44
Top10 Top10 is offline
Friend
 
Join Date: Feb 2017
Posts: 23
Rept. Given: 2
Rept. Rcvd 3 Times in 3 Posts
Thanks Given: 68
Thanks Rcvd at 59 Times in 18 Posts
Top10 Reputation: 3
Its depends on payload's behavior too,if makes many suspicious tasks like add startup key,out connection,copy itself among others,then should be more difficult to hide it to avs.

Depends too of your defense,i mean like anti dumps(try to protect in some way some memory parts), anti emulation and anti debug to avoid av's code emulation and its sandbox.

In personal experience api hook are not needed,you can use other ways like syscalls or change apis flow of your loader or simply both.Here there are some tips about runtime detection:

Quote:
https://blog.cobaltstrike.com/2018/02/08/in-memory-evasion/
Reply With Quote