Understanding the approaches to antivirus research
There are two main approaches to antivirus research. Both ultimately need to lead to the same result, which is always bypassing antivirus software and running malicious code on the user's endpoint.
The two antivirus research approaches are the following:
- Finding a vulnerability in antivirus software
- Using a detection bypass method
As with any code, antivirus software will also contain vulnerabilities that can be taken advantage of. Sometimes, these vulnerabilities may allow controlling the antivirus software's means of detection, prevention, or both.
In upcoming sections, we will look at a few possible vulnerabilities that can help us bypass antivirus software.
Important note
There are a lot of vulnerabilities that we can use to bypass antivirus software, beyond the vulnerabilities we have mentioned in this chapter. For a more comprehensive list of vulnerabilities, check the following link:...