Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

Evasion Engineering

Дата публикации: 02-03-2026 20:41:09

If your tooling is public, it’s already known.
Dennis Chow and Michael LaSalviaJuly 2026

Основное содержимое страницы с новостью.

Evasion Engineering

Building Custom Red Team Tools for Modern Defenses

by Dennis Chow and Michael LaSalvia

Download Chapter 2: Evasion Strategies

Defenders have studied every public offensive framework. They know Cobalt Strike’s beacon patterns, Metasploit’s shellcode signatures, and the behavioral fingerprints of every commodity implant. Once it’s known, the tool gets burned.

As a red teamer, your job is to get in. When defenders know your tools, they know your moves—and you don’t get in. Evasion Engineering teaches you to build custom offensive tooling in Go by understanding what modern defenses actually target and building around them. 

You’ll construct network enumerators, C2 implants, lateral movement tools, obfuscated loaders, and covert exfiltration channels. Each chapter then flips the perspective: the same techniques, examined from the detection side. Build the tool. Understand how it gets caught. Build better.

Dennis Chow (GIAC Security Expert #288) and Michael LaSalvia bring 36 combined years of experience inside Fortune 500 red team programs. They treat payload development as an engineering discipline: robustness, reusability, and reliability built in from the start, not bolted on after the fact.

You’ll learn to:

  • Build enumeration tools that don’t match known signatures 
  • Develop C2 implants with custom protocols that bypass network inspection
  • Implement lateral movement via autonomous worm mechanics
  • Create hybrid-packed payloads that defeat AV and EDR
  • Exfiltrate data through covert channels under active monitoring
  • Map every technique to its detection surface and validate your results

If you’ve been relying on tools the defender already knows, this book is where that changes. 

Requires Go 1.21.x and higher and Python 3.x

Author Bio 

Dennis Chow has worked in penetration testing, cloud security, and detection engineering across Amazon Web Services, UKG, and multiple Fortune 500 companies and US government agencies. He holds the GIAC Security Expert (GSE) certification.

Michael LaSalvia has more than two decades of experience in offensive security and red teaming. Currently a manager of adversarial simulation at Protiviti, he has built and led red team programs for global enterprises including Fidelity National Financial, KPMG, Pfizer, and GSK.

Table of contents 

Foreword
Acknowledgments
Introduction

Part I: Red Teaming Fundamentals
Chapter 1: Principles of Application Design and Development
Chapter 2: Evasion Strategies

Part II: Hands-On Evasive Tool Development
Chapter 3: Enumerating with Traffic Redirection
Chapter 4: Developing Command-and-Control Implants
Chapter 5: Creating Lateral Exploits with Worms
Chapter 6: Enumerating Locally Without LOLBins
Chapter 7: Bypassing Detection with Hybrid Packing
Chapter 8: Staging and Exfiltrating Data Covertly

Part III: Testing and Validation
Chapter 9: Building Detection Tools
Chapter 10: Executing Controlled Reveals

Appendix: Technical Requirements
Index

View the Copyright page
View the detailed Table of Contents
View the Index

Extra Stuff 

Visit the companion repository for a copy of all code, references, and extras on GitHub.

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1Red Team Engineering0518-12-2024
2The Ghidra Book, 2nd Edition0522-07-2025
3Practical AI Security0528-05-2025
4Red Teaming AI0522-07-2025
5Foundations of Cybersecurity, 2nd Edition0307-05-2025
6The Spacecraft Hacker's Handbook0522-07-2025
7The Book of PF, 4th Edition0312-06-2025
8The (Un)Natural History of Malware0502-03-2026
9Heavy Wizardry 1010518-12-2024
10Dissecting the Dark Web0527-05-2025

Классификация: Пресс-релизы. Схожих патентов: 0. Схожих новостей: 10. Тональность: 0. Информативность: 2. Источник: nostarch.com.