What is defence evasion?¶
The practical answer¶
Defence evasion is activity intended to avoid, weaken or bypass security monitoring, prevention or investigation.
The key evidential caution¶
The dangerous assumption is that any change to a security control proves malicious intent.
It may not.
Administrators may disable or reconfigure controls during maintenance, troubleshooting, deployment or incident response.
An offender may attempt to evade defence by:
Key points¶
- disabling security tools
- adding exclusions
- clearing logs
- renaming files
- using trusted tools
- hiding processes
- changing permissions
- obfuscating commands
- deleting artefacts
- routing activity through approved services
What investigators should establish¶
Investigators should establish:
Key points¶
- which control or record was affected
- what account or process made the change
- when it happened
- whether the action succeeded
- what activity followed
- whether legitimate authority existed
- what alternative explanation remains
The presence of an evasion tool or command does not prove it worked.
Evidential limits¶
Likewise, the absence of alerts does not prove monitoring was defeated. Coverage, retention or configuration may already have been limited.
Relevant evidence¶
Relevant evidence may exist in security-product audit logs, policy changes, process activity, command history, account events, provider records and system configuration.
Defence evasion may support intent or awareness of monitoring when linked to later malicious activity.
It does not by itself identify the person responsible.
Where evasion affects several controls, identify the order. An offender may first discover the security product, then alter exclusions, then run a tool and finally remove evidence. That sequence is more informative than one isolated configuration change. Preserve failed attempts and automatic policy restoration as well as successful changes.
Operational takeaway¶
Prove which defence was targeted, what changed and what activity followed, and distinguish deliberate evasion from authorised administration and existing monitoring gaps.