Metasploit-framework: Antivirus Detection : Payload Detected by Symantec and IPS.

Created on 5 May 2017  路  4Comments  路  Source: rapid7/metasploit-framework

While using Meterpreter variations as payload. Now I can bypass Anti-Virus and Firewalls easily, but Symantec Sonar and IPS always detect Meterpreter payloads and block the attacker IP.

Is there any better payload than Meterpreter that can bypass antiviruses like that are used by symantec and IPS ?

Most helpful comment

Symantec detect reverse HTTPS with invalid SSL certificate you can use auxiliary/gather/impersonate_ssl to make correct SSL cert and bypass it.
more info:
https://niiconsulting.com/checkmate/2018/06/bypassing-detection-for-a-reverse-meterpreter-shell/
https://www.netresec.com/index.ashx?page=Blog&month=2011-07&post=How-to-detect-reverse_https-backdoors

All 4 comments

Just encrypt the stage? It's only detecting the stage. Or go stageless.

Sounds about right.

Symantec detect reverse HTTPS with invalid SSL certificate you can use auxiliary/gather/impersonate_ssl to make correct SSL cert and bypass it.
more info:
https://niiconsulting.com/checkmate/2018/06/bypassing-detection-for-a-reverse-meterpreter-shell/
https://www.netresec.com/index.ashx?page=Blog&month=2011-07&post=How-to-detect-reverse_https-backdoors

Nice!!

Was this page helpful?
0 / 5 - 0 ratings

Related issues

BaconBombz picture BaconBombz  路  3Comments

notdodo picture notdodo  路  3Comments

jecoliho picture jecoliho  路  3Comments

ejholmes picture ejholmes  路  3Comments

Acidical picture Acidical  路  3Comments