Detection Evasion
Techniques for evading security tools used by red teams during attack simulations.
Detection evasion and EDR bypass are techniques red teams use to slip past security tools such as EDR and AMSI in order to test whether defenses actually detect an attack. These techniques are applied by Vid Grosek, Slovenia's first OSCE3-certified penetration tester, during authorized red team engagements for organizations in Slovenia and across the EU, delivered through Telprom d.o.o.
Coming soon.
Frequently Asked Questions
What is EDR bypass?
EDR bypass is a technique red teams use to evade endpoint detection and response solutions through command obfuscation, living-off-the-land methods, and modifying malicious code, in order to test how effectively security tools actually detect an attack.
Is detection evasion legal?
Detection evasion is legal only during authorized penetration testing and red team engagements carried out with written permission from the system owner; it is meant for validating defenses and security research, never for unauthorized attacks.
When is detection evasion used in a pentest?
Detection evasion is used during red team engagements when the goal is to simulate a real attacker and assess whether the detection and response team notices and stops the attack, not just whether the systems contain vulnerabilities.