Module 12: Antivirus Alerts and Evasion
Antivirus Basics
Antivirus Overview
Signature-Based Detection
C:\Program Files\Windows Defender>MpCmdRun -Scan -ScanType 3 -File C:\tools\av_alerts_evasion\signature_detect_nonstage.exe -DisableRemediation
Scan starting...
Scan finished.
Scanning C:\tools\av_alerts_evasion\signature_detect_nonstage.exe found 1 threats.
<===========================LIST OF DETECTED THREATS==========================>
----------------------------- Threat information ------------------------------
Threat : Trojan:Win64/Meterpreter.A
Resources : 1 total
file : C:\tools\av_alerts_evasion\signature_detect_nonstage.exe
-------------------------------------------------------------------------------Real-time Heuristic and Behavioral-Based Detection

Antimalware Scan Interface (AMSI)
Understanding AMSI

Bypassing AMSI
Last updated