You must write, compile, and troubleshoot custom C# and PowerShell loaders that inject shellcode while evading Defender and AMSI. The single most important thing is verifying API declarations and obfuscating or encrypting both the payload and the loader so neither static nor AMSI scanning flags them.
Start practicing
Antivirus Evasion — choose a session length
Free · No account required
Domain overview
This domain covers evading Windows Defender, AMSI, and EDR during payload delivery and execution. You must build and modify custom C# and PowerShell loaders, understand how static signatures, AMSI scanning, and behavioral process-creation monitoring detect shellcode, and apply obfuscation, encryption, and API-resolution techniques to reduce detection on target hosts.
Exam objectives
Compiling C# loaders that resolve Win32 APIs like VirtualAlloc, VirtualAllocEx, and CreateRemoteThread correctly
Understanding AMSI scanning of PowerShell and .NET buffers and how to bypass or obfuscate content
Using encryption, encoding, and in-memory execution to defeat static file signatures in Windows Defender
Reducing behavioral detection of process injection and remote thread creation monitored by EDR products
Declaring P/Invoke signatures incorrectly or omitting the required namespace, causing errors like 'VirtualAlloc not found in target assembly scope'
Assuming a compiled loader is undetected without testing against current Defender signatures and AMSI
Encrypting shellcode but leaving the decryption routine or plaintext buffer exposed to AMSI or memory scanning
Click any question to see the full explanation and answer options, or start a focused practice session above.
An analyst is attempting to execute a custom C2 stager on a Windows 10 workstation with active Windows Defender. They decide to use a PowerShell one-liner that downloads a script from a remote server and executes it directly using the Invoke-Expression (IEX) cmdlet. Why is this method generally more effective than downloading an .exe file to the Desktop?
2A penetration tester modifies a known exploit's payload by changing variable names and adding junk instructions. Despite these changes, the antivirus software still flags the file as 'Trojan.Generic' immediately upon being written to disk. What is the most likely reason for this detection?
3Which TWO techniques are primarily used to bypass static signature-based detection by altering the file's binary appearance without changing its underlying functionality?
4An attacker places a malicious 'version.dll' file into the same directory as a legitimate, signed executable that is known to load that DLL. When the legitimate program starts, it loads the malicious DLL instead of the one in the System32 folder. What evasion technique is being demonstrated?
5Which THREE techniques are commonly implemented in malware to detect and evade dynamic analysis within an automated sandbox environment?
6When evaluating an antivirus solution's effectiveness, what is the primary difference between signature-based detection and behavioral-based detection?
7Which TWO methods are effective for obfuscating a PowerShell script to bypass AMSI without modifying the underlying system DLLs?
8A tester is targeting a Windows machine and notices that a specific legitimate application regularly looks for a COM object that is missing from the HKEY_CURRENT_USER (HKCU) registry hive, eventually falling back to HKEY_LOCAL_MACHINE (HKLM). How can this be exploited for evasion?
9Which THREE 'Living off the Land' (LotL) binaries are frequently used by penetration testers to download or execute malicious code while bypassing basic antivirus restrictions?
10A penetration tester uses process hollowing to hide their payload inside 'svchost.exe'. They start the process in a suspended state, unmap its memory, write their shellcode, and resume the thread. What is a specific indicator that an advanced EDR might use to detect this activity?
11Why is using the default 'msfvenom' encoders like 'shikata_ga_nai' often insufficient for bypassing modern antivirus solutions?
12Refer to the exhibit. [!] Error compiling payload: Function 'VirtualAlloc' not found in target assembly scope. An operator is writing a custom process injection loader in C# and encounters the compilation error shown above while attempting to allocate memory for shellcode. How should the operator properly resolve this issue to enable low-level memory allocation?
13When analyzing the memory of a compromised system, you find that your shellcode is being detected by behavioral monitoring. What is the most effective approach to reduce the likelihood of detection by EDR systems during process injection?
14An ethical hacker wants to evade signature-based detection while developing a custom reverse shell loader for a PEN-200 lab assignment. Which technique fundamentally alters the binary's byte signatures without modifying its core execution logic or breaking the payload?
15When evaluating antivirus evasion techniques for Windows targets in a penetration test, which TWO of the following approaches specifically target memory-based detection mechanisms rather than static disk signatures? (Choose TWO)
16An operator is analyzing why a compiled C# stager payload was flagged immediately by Windows Defender despite having a completely unique cryptographic hash. Which AV detection mechanism is most likely responsible for flagging the binary based on internal structure rather than known file signatures?
17Refer to the exhibit. An examiner attempts to use raw msfvenom output directly in a custom C template for a PEN-200 lab assignment, but the payload is instantly detected. Why is generating raw msfvenom output generally ineffective for antivirus evasion without further modification?
18During a PEN-200 lab, a penetration tester develops a custom C# loader that allocates memory, writes shellcode, and executes it. Windows Defender's AMSI flags the process when the shellcode buffer is passed to a scanning routine. The tester wants to prevent AMSI from inspecting the buffer at runtime without disabling Defender. Which technique should the tester apply?
19A penetration tester has obtained a low-privilege shell on a Windows 10 host protected by Windows Defender with real-time protection enabled. The tester wants to execute a custom .NET assembly in memory to avoid writing a payload to disk, but Defender's AMSI integration repeatedly flags the assembly when loaded via the standard reflection technique. Which modification to the in-memory loading approach is MOST likely to prevent AMSI from inspecting the assembly's content?
20During a PEN-200 lab engagement, a tester delivers a custom C# implant compiled with csc.exe. Windows Defender's real-time protection immediately quarantines the executable at rest on disk, before any process is created. The tester wants to keep the same implant logic but reduce static file-based detection. Which approach best addresses this specific detection stage?
21During an authorized penetration test, a tester needs to deliver a Meterpreter payload to a Windows Server 2019 target that runs a next-generation antivirus with behavioral monitoring. The tester decides to use a process injection technique to run the payload inside a legitimate process. Which injection method is LEAST likely to be flagged by behavioral monitoring because it avoids allocating new executable memory in the target process?
22A penetration tester has a working unmanaged PowerShell runner in C# that executes a script block on a Windows 10 host with AMSI enabled. The runner currently fails because AMSI scans the script content. The tester wants to disable AMSI scanning for the current process without touching files on disk and without requiring administrative privileges. Which technique best fits these constraints?
23A junior penetration tester is preparing a payload for a Windows 10 target with Windows Defender enabled. The tester wants to avoid writing the payload to disk and decides to use a PowerShell one-liner that downloads and executes a script in memory. Which PowerShell feature allows the script to be executed directly from a downloaded string without saving it to a file?
24A tester is preparing a reverse shell executable for a Windows target protected by a signature-based antivirus product. To reduce the chance the file is flagged, the tester wants to modify the binary so it no longer matches known signatures while keeping its behavior. Which action best accomplishes this?
25A penetration tester delivers a custom .NET executable to a Windows 10 host running Microsoft Defender with cloud-delivered protection enabled. The binary contains an embedded shellcode blob in its .data section. After the loader decrypts the shellcode in memory and begins executing it, Defender terminates the process even though the file itself never touched disk again. Which technique would most directly address this specific detection?
26You are tasked with delivering a Meterpreter payload to a Windows Server 2019 target protected by a next-generation antivirus that performs userland API hooking on NtAllocateVirtualMemory and NtProtectVirtualMemory. Your current C loader uses these APIs directly and is detected. Which technique is most appropriate to bypass the userland hooks without requiring kernel-level privileges?
27A penetration tester is preparing a Windows payload for a client engagement where the target endpoint runs a traditional signature-based antivirus product that does not perform cloud lookups. The tester wants to reduce the chance that the raw output of msfvenom is flagged during initial delivery. Which action best addresses this goal?
28A penetration tester is preparing to bypass antivirus on a Windows target during a PEN-200 lab. The tester wants to use packing and encryption to alter the payload's signature and avoid static detection. Which TWO techniques are effective for evading static signature-based detection by changing the file's binary appearance without altering its functionality? (Choose two.)
29A penetration tester is building a custom shellcode runner in C for a PEN-200 lab. The compiled loader is being flagged by static analysis before execution. The tester wants to modify the loader's source so the resulting binary is less likely to match signatures, without changing the shellcode's behavior. Which two changes best serve this goal? (Choose two.)
30During a red team engagement, a tester writes a C# loader that calls the Win32 API function VirtualAllocEx to allocate memory in a remote process, writes shellcode, and creates a remote thread. The loader compiles and runs, but the endpoint's EDR blocks it before the remote thread executes. The tester confirms the EDR is hooking user-mode API functions in ntdll.dll. Which approach most directly avoids the user-mode hooks that triggered the block?
31A penetration tester has a working PowerShell-based stager that is being blocked by AMSI on a Windows 11 target. The tester wants to keep using PowerShell for convenience but needs the stager to run without AMSI inspecting the script content. Which technique most directly targets AMSI's inspection of the script?
32A penetration tester needs to deliver a Meterpreter payload to a Windows target protected by an EDR that performs both static file scanning and behavioral monitoring of process creation. The tester wants to reduce the chance of detection during initial execution while still obtaining a session. Which two techniques most directly reduce detection in this combined scenario? (Choose two.)
33A junior penetration tester is preparing a payload for a Windows 10 target and wants to avoid signature-based detection by changing the binary's appearance without altering its functionality. Which technique is specifically designed to achieve this?
34A penetration tester has written a C# loader that reads shellcode from a file, allocates memory with VirtualAlloc using PAGE_EXECUTE_READWRITE, and executes it via CreateThread. The loader is not detected by static antivirus signatures, but when run on a Windows 10 host with Microsoft Defender's real-time protection enabled, the process is terminated shortly after execution begins. The tester suspects behavior-based detection. Which modification is MOST likely to prevent this behavioral detection while preserving execution?
You must write, compile, and troubleshoot custom C# and PowerShell loaders that inject shellcode while evading Defender and AMSI. The single most important thing is verifying API declarations and obfuscating or encrypting both the payload and the loader so neither static nor AMSI scanning flags them.
The Courseiva PEN-200 question bank contains 34 questions in the Antivirus Evasion domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Antivirus Evasion domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included