Catch Me If You Can: Detector-Resistant Evasion via Semantics-Preserving Command Re-Realization
Muhammad Shoaib, Hare Sudhan Muthusamy, Tareq Alkhatib, Wajih Ul Hassan
Abstract
Red teams require evasion techniques to test Security Information and Event Management (SIEM) detection rules, yet existing approaches are (1) manual, (2) rely on stringlevel obfuscations (such as encoding schemes and quoting tricks) that are easily reversed by de-obfuscators, and (3) provide limited rule coverage. This leaves unexplored semanticpreserving evasions that achieve identical effects through different utilities, preventing assessment of whether rules detect attack intent or merely surface patterns. We present Spectra, an automated evasion generator that preserves attack effects while transforming command-line realization through functionally equivalent utilities and argument structures. By reasoning over semantic representations rather than syntactic patterns, Spectra automatically generates more durable and effective evasions. On Windows Sigma process_creation rules, Spectra achieves 72.9 % rule coverage compared to 37.6 % for AMIDES (the state-of-the-art method), with only 4.5% of evasions reversed by de-obfuscators versus 78.1% for AMIDES (17.4 times more resistant). When evaluated against the state-of-the-art evasion detector at its zero-falsepositive operating point, Spectra achieves a detection rate of only 22.7 % compared to 69.9 % for AMIDES. SPECTRA also outperforms five general-purpose LLMs across metrics.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 8a88ba7c-9449-4330-8d0a-7f196b956e86Cited by top-tier papers1
Ask how each one uses itRelated papers
- You Cannot Escape Me: Detecting Evasions of SIEM Rules in Enterprise NetworksRafael Uetz, Marco Herzog, Louis Hackländer, Simon Schwarz et al.USENIX Security 2024 · 23 citations
- From Texts to Rules: Generating Sigma Rules with Large Language Models from Cyber Threat ReportsYongxin Cai, Jing Qiu, Qingming Li, Du Cheng et al.USENIX Security 2026
- A Context Is Worth a Thousand Lies: Evading Intrusion Detectors via Intelligent Context DistortionMagdy Nasr, Vansh Rastogi, Azadeh TabibanBS&P 2026 · 1 citation
- Credible Threat Detection? Measuring Contribution Dynamics and Quality Control in a Crowdsourced Threat Detection EcosystemApurva Virkud, Gang Wang, Adam BatesUSENIX Security 2026 · 1 citation
- RulePilot: An LLM-Powered Agent for Security Rule GenerationHongtai Wang, Ming Xu, Yanpei Guo, Weili Han et al.ICSE 2026 · 1 citation
