Today's sophisticated attacks, like those we see coming from threat actors such as FIN8, FIN7, and FIN6, are engineered to bypass EDR solutions. They choose when, where and how to attack, knowing the various detection methods used by those systems. In the presentation, we will look at these case studies and cover the different relevant techniques employed by the advanced groups to bypass behavior-based solutions, static-based scanning solutions, and whitelisting-based solutions. We'll practically demonstrate those bypass techniques by using a framework developed for Red Teamers called TotalEvasion, which is derived from the Inception, SharpShooter, DotNetToJScript and Metasploit frameworks, and is based on a set of widely-deployed fileless attack techniques. We will examine in detail the full attack chain of a fileless, living-off-the-land attack, looking at the various mechanisms used by security tools to detect attacks, and analyzing each stage of the attack to understand the evasive techniques it uses to remain undetected.Attendees will deconstruct the various mechanisms security tools employ to detect attacks and learn more about the evasive techniques attacks use at every stage to remain undetected.Attendees will be able to connect their knowledge from the defense and attack aspects of cybersecurity to gain a deeper understanding of the way advanced attacks are engineered to bypass EDR.Attendees will also be exposed to the TotalEvasion pentesting tool, a non-commercial pentesting framework that is available to qualified researchers and testers.