1"use strict";(self.webpackChunkveil_framework=self.webpackChunkveil_framework||[]).push([[5030],{5609:function(e,t,n){n.r(t),n.d(t,{Head:function(){return f},default:function(){return h}});var a=n(8453),l=n(6540);function r(e){const t=Object.assign({h1:"h1",p:"p",em:"em",a:"a",h2:"h2",h3:"h3",ul:"ul",li:"li",strong:"strong"},(0,a.RP)(),e.components);return l.createElement(l.Fragment,null,l.createElement(t.h1,null,"Veil-Evasion"),"\n",l.createElement(t.p,null,"Veil-Evasion is the payload generation engine at the heart of the framework. It produces executables and scripts designed to test whether endpoint detection systems identify specific evasion techniques. This page covers the module's architecture, its role in detection research, and the defensive strategies that make evasion testing valuable."),"\n",l.createElement(t.p,null,l.createElement(t.em,null,"(This page is also accessible via the legacy path ",l.createElement(t.a,{href:"/framework/veil/evasion/"},"/framework/veil/evasion/")," for historical backlink compatibility.)")),"\n",l.createElement(t.p,null,"If you have spent any time in purple team exercises, you know the frustration of discovering that your EDR was tuned for last year's threats. Evasion testing with a structured tool like this reveals exactly where those gaps are â not in theory, but against your actual deployment."),"\n",l.createElement(t.h2,null,'What "Evasion" Means in Security Testing'),"\n",l.createElement(t.p,null,"Evasion, in the context of penetration testing, refers to generating payloads that avoid detection by specific security controls. The purpose is diagnostic: if your antivirus or EDR does not flag a known evasion technique, you have a detection gap that needs addressing."),"\n",l.createElement(t.p,null,'This is fundamentally a defensive exercise. The goal is never to "bypass all AV" â that framing misunderstands the purpose. Real-world evasion testing operates within a feedback loop: generate, deploy, observe, detect, tune, repeat. Each cycle strengthens your detection posture.'),"\n",l.createElement(t.h2,null,"Detection-First Approach"),"\n",l.createElement(t.p,null,"Before you generate a single payload, your monitoring infrastructure needs to be in place. Without telemetry, evasion testing is noise."),"\n",l.createElement(t.h3,null,"Logging Requirements"),"\n",l.createElement(t.p,null,"At minimum, ensure these are configured in your lab environment:"),"\n",l.createElement(t.ul,null,"\n",l.createElement(t.li,null,l.createElement(t.strong,null,"Sysmon")," â Process creation (Event ID 1), network connections (Event ID 3), file creation (Event ID 11), and image load events (Event ID 7). The SwiftOnSecurity Sysmon configuration is a reasonable starting point, but you will likely need to tune it for your specific exercise."),"\n",l.createElement(t.li,null,l.createElement(t.strong,null,"PowerShell logging")," â Script block logging (Event ID 4104), module logging, and transcription. These are essential if you are testing PowerShell-based payloads."),"\n",l.createElement(t.li,null,l.createElement(t.strong,null,"Windows Event Forwarding")," â Centralize your logs. Reviewing events across twenty machines locally is not practical."),"\n",l.createElement(t.li,null,l.createElement(t.strong,null,"EDR telemetry")," â If your organization uses CrowdStrike, SentinelOne, Defender for Endpoint, or similar, put agents on your lab targets in audit mode."),"\n"),"\n",l.createElement(t.h3,null,"What to Watch For"),"\n",l.createElement(t.p,null,"When a Veil-Evasion payload executes in your lab, your detection stack should ideally capture:"),"\n",l.createElement(t.ul,null,"\n",l.createElement(t.li,null,"Process creation with suspicious parent-child relationships"),"\n",l.createElement(t.li,null,"Network callbacks to your listener"),"\n",l.createElement(t.li,null,"Memory allocation patterns consistent with shellcode injection"),"\n",l.createElement(t.li,null,"File writes to temp directories"),"\n",l.createElement(t.li,null,"Unsigned or anomalous executables"),"\n"),"\n",l.createElement(t.p,null,"If you see none of these in your logs, your detection has blind spots that need immediate attention."),"\n",l.createElement(t.h2,null,"Supported Output Formats"),"\n",l.createElement(t.p,null,"Evasion supports multiple payload languages and output types:"),"\n",l.createElement(t.ul,null,"\n",l.createElement(t.li,null,l.createElement(t.strong,null,"Python")," â Compiled via PyInstaller; useful for cross-platform testing"),"\n",l.createElement(t.li,null,l.createElement(t.strong,null,"C")," â Compiled to native PE; tests signature-based and heuristic detection"),"\n",l.createElement(t.li,null,l.createElement(t.strong,null,"PowerShell")," â Script-based; exercises script block logging and AMSI"),"\n",l.createElement(t.li,null,l.createElement(t.strong,null,"Ruby")," â Less common but useful for testing edge cases in detection rules"),"\n"),"\n",l.createElement(t.p,null,"Each format interacts differently with security controls. C-compiled payloads test traditional AV signatures and heuristic engines. PowerShell payloads test script-based detection, AMSI integration, and constrained language mode. The variety matters because detection teams need coverage across all vectors."),"\n",l.createElement(t.h2,null,"Safety and Legality"),"\n",l.createElement(t.p,null,"Every test using Veil-Evasion must occur in an environment where you have explicit written authorization. This is not optional â it is a legal requirement in virtually every jurisdiction. Generate payloads in your lab. Test them against your targets. Do not move generated files to production networks or personal devices outside your lab boundary."),"\n",l.createElement(t.p,null,"The techniques exercised here are the same ones real-world attackers deploy against individuals and organizations. If you are also thinking about your own exposure beyond the lab, ",l.createElement(t.a,{href:"https://techitez.org/cryptocurrency/how-to-avoid-getting-hacked-7-best-practices-for-crypto-investors/"},"understanding how to avoid getting hacked")," covers the defensive hygiene practices that complement this kind of offensive research."),"\n",l.createElement(t.p,null,"When you have finished testing, securely delete generated payloads. Leaving evasion payloads on disk, even in a lab, creates unnecessary risk and clutters your environment."),"\n",l.createElement(t.h2,null,"Detection Context: MITRE ATT&CK Mapping"),"\n",l.createElement(t.p,null,"Understanding where evasion techniques map to established frameworks helps defensive teams prioritize their detection efforts. The ",l.createElement(t.a,{href:"https://attack.mitre.org/tactics/TA0005/"},"MITRE ATT&CK matrix for Defense Evasion (TA0005)")," catalogs the techniques that payload generators like Veil-Evasion implement â from obfuscated files (T1027) to process injection (T1055) to signed binary proxy execution (T1218)."),"\n",l.createElement(t.p,null,"Mapping your Veil-Evasion test cases to ATT&CK technique IDs allows you to systematically track which techniques your detection stack covers and which remain blind spots. This is how you turn ad-hoc testing into structured coverage measurement."),"\n",l.createElement(t.h2,null,"Where to Go Next"),"\n",l.createElement(t.ul,null,"\n",l.createElement(t.li,null,l.createElement(t.strong,null,l.createElement(t.a,{href:"/veil-tutorial/"},"Veil Tutorial"))," â Walkthrough of first-time setup and basic usage"),"\n",l.createElement(t.li,null,l.createElement(t.strong,null,l.createElement(t.a,{href:"/veil-command-line-usage/"},"Command-Line Usage"))," â Complete CLI reference"),"\n",l.createElement(t.li,null,l.createElement(t.strong,null,l.createElement(t.a,{href:"/powershell-payloads/"},"PowerShell Payloads"))," â PowerShell-specific considerations"),"\n",l.createElement(t.li,null,l.createElement(t.strong,null,l.createElement(t.a,{href:"/how-to-safely-check-veil-payloads-against-virustotal/"},"Safely Checking Payloads Against VirusTotal"))," â Detection rate evaluation"),"\n",l.createElement(t.li,null,l.createElement(t.strong,null,l.createElement(t.a,{href:"/framework/"},"Framework Overview"))," â How Evasion fits into the broader architecture"),"\n"))}var s=function(e={}){const{wrapper:t}=Object.assign({},(0,a.RP)(),e.components);return t?l.createElement(t,e,l.createElement(r,e)):r(e)},i=n(9329),o=n(1744),c=n(8963),m=n(8752),u=n(7304);function d(e){if(!e)return null;try{return new Intl.DateTimeFormat("en-GB",{day:"numeric",month:"long",year:"numeric",timeZone:"UTC"}).format(new Date(e))}catch{return null}}function p({pageContext:e,children:t}){const{frontmatter:n}=e,a=(null==n?void 0:n.title)||"",r=(null==n?void 0:n.description)||"",s=(null==n?void 0:n.slug)||"",o=(null==n?void 0:n.heroImage)||null,p=(null==n?void 0:n.date)||null,h=(null==n?void 0:n.lastmod)||null,f=d(p),E=h&&h!==p?d(h):null;return l.createElement(i.A,null,o&&l.createElement(c.A,{title:a,subtitle:r,backgroundImage:o}),l.createElement("article",{className:"page-content"},l.createElement("div",{className:"container"},f&&l.createElement("p",{className:"post-meta"},l.createElement("time",{dateTime:p},"Published ",f),E&&l.createElement(l.Fragment,null," · ",l.createElement("time",{dateTime:h}
1,"Updated ",E))),l.createElement("div",{className:"post-layout-grid"},l.createElement("div",{className:"post-main"},t),l.createElement("aside",{className:"post-sidebar","aria-label":"Sidebar"},l.createElement("div",{className:"post-sidebar-scroll"},l.createElement(u.A),l.createElement(m.A,{sourceUrl:s})))))))}function h(e){return l.createElement(p,e,l.createElement(s,e))}function f({pageContext:e}){const{frontmatter:t}=e,n=null!=t&&t.heroImage?`https://www.veil-framework.com${t.heroImage}`:null;return l.createElement(o.A,{title:null==t?void 0:t.title,description:null==t?void 0:t.description,pathname:null==t?void 0:t.slug},(null==t?void 0:t.date)&&l.createElement("meta",{property:"article:published_time",content:t.date}),(null==t?void 0:t.lastmod)&&l.createElement("meta",{property:"article:modified_time",content:t.lastmod}),n&&l.createElement("meta",{property:"og:image",content:n}),n&&l.createElement("meta",{name:"twitter:image",content:n}))}},7304:function(e,t,n){n.d(t,{A:function(){return r}});var a=n(6540);function l({href:e,children:t,className:n,...l}){return a.createElement("a",Object.assign({href:e,target:"_blank",rel:"sponsored nofollow noopener",className:n},l),t)}function r(){const e="/veil-recommends/infosec-fundamentals";return a.createElement("aside",{className:"fc-wrap","aria-label":"Recommended course"},a.createElement("div",{className:"fc-header"},a.createElement("span",{className:"fc-dot fc-dot-r","aria-hidden":"true"}),a.createElement("span",{className:"fc-dot fc-dot-a","aria-hidden":"true"}),a.createElement("span",{className:"fc-dot fc-dot-g","aria-hidden":"true"}),a.createElement("span",{className:"fc-header-label"},"course_spotlight.sh")),a.createElement(l,{href:e,className:"fc-image-link","aria-label":"View Information Security Fundamentals course"},a.createElement("img",{src:"/img/hero/infosec-fundamentals.webp",alt:"Information Security Fundamentals course cover",className:"fc-image",loading:"lazy",width:"300",height:"169"})),a.createElement("div",{className:"fc-body"},a.createElement("div",{className:"fc-tag"},"Recommended Course"),a.createElement("h3",{className:"fc-title"},a.createElement(l,{href:e,className:"fc-title-link"},"Information Security Fundamentals")),a.createElement("p",{className:"fc-desc"},"Build a solid foundation in cybersecurity. Covers network fundamentals, common attack vectors, defensive controls, and the mindset needed for security research."),a.createElement("ul",{className:"fc-features"},a.createElement("li",{className:"fc-feature"},a.createElement("span",{className:"fc-feature-icon","aria-hidden":"true"},"â¸"),"Beginner-friendly â no prior experience needed"),a.createElement("li",{className:"fc-feature"},a.createElement("span",{className:"fc-feature-icon","aria-hidden":"true"},"â¸"),"Network attacks & defences"),a.createElement("li",{className:"fc-feature"},a.createElement("span",{className:"fc-feature-icon","aria-hidden":"true"},"â¸"),"Real-world security concepts")),a.createElement(l,{href:e,className:"fc-cta"},"View Course",a.createElement("span",{className:"fc-cta-arrow","aria-hidden":"true"}," â")),a.createElement("p",{className:"fc-disclosure"},"We may earn a commission if you enrol via our link, at no extra cost to you.")))}},8453:function(e,t,n){n.d(t,{RP:function(){return r}});var a=n(6540);const l=a.createContext({});function r(e){const t=a.useContext(l);return a.useMemo(()=>"function"==typeof e?e(t):{...t,...e},[t,e])}},8752:function(e,t,n){n.d(t,{A:function(){return l}});var a=n(6540);function l({sourceUrl:e}){const{0:t,1:n}=(0,a.useState)("idle"),{0:l,1:r}=(0,a.useState)("");return a.createElement("aside",{className:"nl-sw-wrap","aria-label":"Newsletter signup"},a.createElement("div",{className:"nl-sw-header"},a.createElement("span",{className:"nl-sw-dot nl-sw-dot-r","aria-hidden":"true"}),a.createElement("span",{className:"nl-sw-dot nl-sw-dot-a","aria-hidden":"true"}),a.createElement("span",{className:"nl-sw-dot nl-sw-dot-g","aria-hidden":"true"}),a.createElement("span",{className:"nl-sw-title"},"intel_feed.sh")),a.createElement("div",{className:"nl-sw-body"},a.createElement("p",{className:"nl-sw-prompt"},a.createElement("span",{className:"nl-sw-caret","aria-hidden":"true"},"$")," ","subscribe --to evasion-intel"),a.createElement("h3",{className:"nl-sw-heading"},"Stay ahead of the curve"),a.createElement("p",{className:"nl-sw-desc"},"AV bypass techniques, detection gaps, and lab-tested research â delivered before the mainstream catches up."),"done"===t?a.createElement("div",{className:"nl-sw-success",role:"status"},a.createElement("span",{className:"nl-sw-check","aria-hidden":"true"},"â"),a.createElement("div",null,a.createElement("strong",null,"Subscribed."),a.createElement("br",null),a.createElement("span",{className:"nl-sw-success-sub"},"Confirm your email to activate."))):a.createElement("form",{onSubmit:async function(e){e.preventDefault();const t=e.currentTarget,a=new FormData(t);
1if(!a.get("company")){n("loading"),r("");try{const e=await fetch("/api/subscribe",{method:"POST",body:a}),l=await e.json();l.success?(n("done"),t.reset()):(n("err"),r(l.error||"Something went wrong."))}catch{n("err"),r("Network error â please try again.")}}},className:"nl-sw-form",noValidate:!0},a.createElement("input",{type:"hidden",name:"site",value:"veil-framework"}),a.createElement("input",{type:"hidden",name:"source_url",value:e||""}),a.createElement("input",{type:"text",name:"company",tabIndex:"-1","aria-hidden":"true",className:"nl-sw-hp",autoComplete:"off"}),a.createElement("label",{htmlFor:"nl-sw-name",className:"nl-sw-label"},"Your name"),a.createElement("input",{id:"nl-sw-name",type:"text",name:"name",placeholder:"alias or handle",required:!0,autoComplete:"given-name",className:"nl-sw-input",disabled:"loading"===t}),a.createElement("label",{htmlFor:"nl-sw-email",className:"nl-sw-label"},"Email address"),a.createElement("input",{id:"nl-sw-email",type:"email",name:"email",placeholder:"[email protected]",required:!0,autoComplete:"email",className:"nl-sw-input",disabled:"loading"===t}),"err"===t&&a.createElement("p",{className:"nl-sw-error",role:"alert"},l),a.createElement("button",{type:"submit",className:"nl-sw-btn",disabled:"loading"===t},"loading"===t?"Connectingâ¦":"Subscribe to intel â"),a.createElement("p",{className:"nl-sw-legal"},"No spam. No vendor fluff. Unsubscribe any time."))))}},8963:function(e,t,n){n.d(t,{A:function(){return l}});var a=n(6540);function l({title:e,subtitle:t,primaryLink:n,primaryText:l,secondaryLink:r,secondaryText:s,backgroundImage:i}){const o=i?{backgroundImage:`linear-gradient(135deg, rgba(37, 99, 235, 0.85) 0%, rgba(13, 33, 55, 0.9) 100%), url(${i})`,backgroundSize:"cover",backgroundPosition:"center"}:{};return a.createElement("section",{className:"hero blueprint-section-subtle",style:o},a.createElement("div",{className:"container"},a.createElement("h1",null,e),t&&a.createElement("p",null,t),(n||r)&&a.createElement("div",{style:{display:"flex",gap:"var(--space-md)",flexWrap:"wrap"}},n&&a.createElement("a",{href:n,className:"btn btn-primary"},l||"Get Started"),r&&a.createElement("a",{href:r,className:"btn btn-outline"},s||"Learn More"))))}}}]); 2//# sourceMappingURL=component---src-components-page-template-jsx-content-file-path-content-pages-veil-evasion-mdx-5337a97789d8fd1f44f9.js.map
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.