Skip to content
CIM-219 Cyber Incidents & Offender Methods

What is defence evasion?

The practical answer

Defence evasion is activity intended to avoid, weaken or bypass security monitoring, prevention or investigation.

The key evidential caution

The dangerous assumption is that any change to a security control proves malicious intent.

It may not.

Administrators may disable or reconfigure controls during maintenance, troubleshooting, deployment or incident response.

An offender may attempt to evade defence by:

Key points

  • disabling security tools
  • adding exclusions
  • clearing logs
  • renaming files
  • using trusted tools
  • hiding processes
  • changing permissions
  • obfuscating commands
  • deleting artefacts
  • routing activity through approved services

What investigators should establish

Investigators should establish:

Key points

  • which control or record was affected
  • what account or process made the change
  • when it happened
  • whether the action succeeded
  • what activity followed
  • whether legitimate authority existed
  • what alternative explanation remains

The presence of an evasion tool or command does not prove it worked.

Evidential limits

Likewise, the absence of alerts does not prove monitoring was defeated. Coverage, retention or configuration may already have been limited.

Relevant evidence

Relevant evidence may exist in security-product audit logs, policy changes, process activity, command history, account events, provider records and system configuration.

Defence evasion may support intent or awareness of monitoring when linked to later malicious activity.

It does not by itself identify the person responsible.

Where evasion affects several controls, identify the order. An offender may first discover the security product, then alter exclusions, then run a tool and finally remove evidence. That sequence is more informative than one isolated configuration change. Preserve failed attempts and automatic policy restoration as well as successful changes.

Operational takeaway

Prove which defence was targeted, what changed and what activity followed, and distinguish deliberate evasion from authorised administration and existing monitoring gaps.

Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.