Last updated: April 29, 2026
Defender perspective on red-team payload development. Modern AV/EDR catches commodity payloads; serious red teams build custom.
Layers of evasion
- Loader — small program that decrypts/decompresses real payload
- Shellcode encoding — XOR, custom crypto, polymorphism
- API resolution at runtime — don’t import suspicious functions in IAT
- Sleep + jitter — long sleeps between actions to defeat memory scanners
- Direct syscalls — bypass user-mode hooks
- Process hollowing / herpaderping — execute in legitimate process context
Custom team training + practitioner advisory
Beyond the free academy — we run private workshops, vCISO advisory, and red-team exercises tailored to your stack. For Indian SMBs scaling past their first hire.