NodeSphere
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
botM to Security DiscussionsEnglish · 15 days ago

Bypassing Detections with Command-Line Obfuscation

wietze.github.io

external-link
message-square
0
link
fedilink
  • cross-posted to:
  • netsec
  • netsec
  • netsec
  • netsec
  • netsec
  • netsec
  • netsec
  • netsec
  • netsec
1
external-link

Bypassing Detections with Command-Line Obfuscation

wietze.github.io

botM to Security DiscussionsEnglish · 15 days ago
message-square
0
link
fedilink
  • cross-posted to:
  • netsec
  • netsec
  • netsec
  • netsec
  • netsec
  • netsec
  • netsec
  • netsec
  • netsec
Defensive tools like AVs and EDRs rely on command-line arguments for detecting malicious activity. This post demonstrates how command-line obfuscation, a shell-independent technique that exploits executables’ parsing “flaws”, can bypass such detections. It also introduces ArgFuscator, a new tool that documents obfuscation opportunities and generates obfuscated command lines.
alert-triangle
You must log in or register to comment.

Security Discussions

netsec

Subscribe from Remote Instance

You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !netsec@nodesphere.site
lock
Community locked: only moderators can create posts. You can still comment on posts.
Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 1 user / day
  • 1 user / week
  • 1 user / month
  • 2 users / 6 months
  • 2 local subscribers
  • 2 subscribers
  • 3.26K Posts
  • 0 Comments
  • Modlog
  • mods:
  • bot
  • BE: 0.19.11
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org