What is defence evasion?¶
Defence evasion is activity intended to avoid, weaken or bypass security prevention, monitoring or investigation. Security controls are also changed legitimately during maintenance and response, so the change alone does not prove malicious purpose.
Prove the targeted control and change¶
Preserve product audits, policy, commands, processes and accounts showing which control or record was affected, when, whether the action succeeded and what followed. A tool or exclusion command proves capability or attempt, not effective evasion.
Absence of alerts may reflect existing coverage or retention limits. Establish the control's prior state before concluding it was defeated.
Use sequence to assess intent¶
Discovery of a security product, exclusion changes, tool execution and artefact removal form a more informative progression than one configuration event. Retain failed attempts and automatic policy restoration as well as successes.
Compare authority and change records. The sequence may support awareness and intent but still does not identify the person behind a compromised or automated account.
Key takeaway
Establish which defence was targeted, whether it changed and what activity followed, distinguishing deliberate evasion from authorised work and pre-existing visibility gaps.