@Alh4zr3d
I remember watching his streams on youtube few years back. OG at breaking stuff down making it digestible.
His tips are golden. I picked up so much from him thats its unreal.
@justmyownenemy@vxunderground I think Evasion is a subset of Maldev and not the other way around. The op is trying to say that, most courses that claim maldev actually delivers evasion tactics. Makes sense ngl.
@I_Am_Jakoby@justmyownenemy Buddy i like your work, but in honesty this is not evasion or bypass. A rev shell compiled in any language with basic api hashing will not be marked malicious natively by AV/EDR depending on the engine.
Mature solution monitor call stack, even the most basic AVs.
@0xBoku@cyb3rops@hasherezade Blue team todolist be like:
1. Dont share detection tools online
2. Dont want to improve knowledge on latest TTPs
3. Sell snake oil EDR for millions
4. Cant detect shit
5. Blame offsec tooling
6. Tweet red team helps threat actors
7. loop
We'll tell you a secret. Not very many people know this.
Most malware development courses and papers cover the same material: process injection, persistence, basic anti-reverse engineering techniques, etc
This doesn't scratch the surface of what malware or malware research is.