Defense Evasion
Adversaries invest heavily in remaining undetected. Defense evasion techniques disable security tools, remove evidence, and obfuscate malicious activity. ManySignal's immutable log ingestion and behavioural analytics detect these techniques even when attackers try to cover their tracks.
Coverage
- Techniques covered
- 42
- Detection rules
- 74
- Log-tamper rules
- 14
Threat context
How adversaries evade detection
Defense evasion is where sophisticated adversaries differentiate themselves. Commodity attackers trigger obvious alerts; nation-state actors and experienced ransomware operators disable logging, clear event logs, and operate under legitimate credentials before deploying their primary payload. The goal is to extend dwell time — the longer they operate undetected, the more damage they can inflict or data they can exfiltrate.
ManySignal counters evasion through immutable log ingestion (events are stored in ManySignal before attackers can delete local copies), behavioural anomaly detection (operating under a valid account still leaves behavioural traces), and connector health monitoring (a silenced data source is itself an alert).
Techniques
Defense Evasion techniques ManySignal detects
Impair Defenses
Disabling CloudTrail, GuardDuty, EDR agents, or Windows audit logging.
Indicator Removal
Log clearing, file deletion, command history wiping, and timestomping.
Obfuscated Files or Information
Base64 encoding, string obfuscation, and packed executables to evade signature detection.
Abuse Elevation Control Mechanism
UAC bypass to execute with elevated privileges without a visible prompt.
Use Alternate Authentication Material
Pass-the-Hash, Pass-the-Ticket, and web session cookie replay.
Valid Accounts
Operating under legitimate user credentials to blend with normal traffic.
Defense Evasion: frequently asked questions
What is ATT&CK Defense Evasion (TA0005)?
Defense Evasion covers techniques adversaries use to avoid detection and analysis by security tools. It is the most diverse ATT&CK tactic with over 40 techniques, reflecting how much adversaries invest in staying hidden.
How does ManySignal detect log tampering if the logs are cleared?
ManySignal ingests logs as they are generated and ships them to its own storage immediately. Clearing local Windows Event Logs or disabling CloudTrail removes the local copy but not what ManySignal has already ingested. The clearing event itself generates a high-priority alert.
Can attackers disable ManySignal itself?
ManySignal's connectors run as separate processes with minimal footprint. Disabling them requires platform-level access. ManySignal monitors connector health and alerts when event delivery stops unexpectedly — a connector going silent is itself a defense evasion indicator.
Detect evasion before attackers disappear into the noise
ManySignal's immutable log ingestion and behavioural analytics catch defense evasion techniques even when attackers disable local logging.