From the course: Metasploit Essential Training

Unlock the full course today

Join today to access over 24,700 courses taught by industry experts.

Understand how to bypass antivirus

Understand how to bypass antivirus

From the course: Metasploit Essential Training

Understand how to bypass antivirus

- [Instructor] Understanding how to bypass antivirus. The purpose of an encoder is to handle bad characters when you write exploits. Encoders are not meant for antivirus evasion. Sometimes, however, antivirus evasion is a byproduct of encoding, but it is not guaranteed. One of the best ways to avoid being stopped by antivirus software is to encode payloads with msfvenom. Msfvenom is a useful tool that alters the code in an executable, so it looks different to antivirus software, but will still run the same anyway. Antivirus signatures are frequently updated to detect new and change payloads. Within the framework, you can get a better results through multi-encoding, which allows the payload to be encoded several times to throw off antivirus programs that check for signatures. Typically, when msf is ran, the payload is embedded into the default executable template, which is found in data/templates/template.xe. Although…

Contents