Noob 101: Practical Techniques for AV Bypass

No ratings

Presented at Anycon 2017 by

The shortcomings of anti-virus (AV) solutions have been well known for some time. Nevertheless, both public and private organizations continue to rely on AV software as a critical component of their information security programs, acting as a key protection mechanism over endpoints and other information systems within their networks. As a result, the security posture of these organizations is significantly jeopardized by relying only on this weakened control. This presentation will discuss and demonstrate some of the options available to bypass AV controls in order to deliver a variety of payloads to a targeted system. This includes using publicly available tools to generate these payloads, coding and compiling custom binaries with the Python and C++ programming languages, and leveraging the native Windows management framework PowerShell to deliver and execute payloads directly from the target system’s memory. Further, beyond just avoiding signature based AV detection, this presentation will also discuss some techniques to consider to avoid heuristic, or behavioral based detection as well. This presentation reinforces the need for all organizations, whether public or private, to have a comprehensive security program in place to safeguard their informational assets. This includes a security program that practices a defense-in-depth approach, and is not reliant on a single control for wide-ranging protection to address all possible threats.