Catch Me If You Can: Detector-Resistant Evasion via Semantics-Preserving Command Re-Realization
Research Paper Showcase 2026
Abstract
Red teams require evasion techniques to test Security Information and Event Management (SIEM) detection rules, yet existing approaches are (1) manual, (2) rely on string-level obfuscations (such as encoding schemes and quoting tricks) that are easily reversed by de-obfuscators, and (3) provide limited rule coverage. This leaves unexplored semantic-preserving evasions that achieve identical effects through different utilities, preventing assessment of whether rules detect attack intent or merely surface patterns. We present SPECTRA, an automated evasion generator that preserves attack effects while transforming command-line realization through functionally equivalent utilities and argument structures. By reasoning over semantic representations rather than syntactic patterns, SPECTRA automatically generates more durable and effective evasions. On Windows Sigma process_creation rules, SPECTRA achieves 72.9% rule coverage compared to 37.6% for AMIDES (the state-of-the-art method), with only 4.5% of evasions reversed by de-obfuscators versus 78.1% for AMIDES (17.4 times more resistant). When evaluated against the state-of-the-art evasion detector at its zero-false-positive operating point, SPECTRA achieves a detection rate of only 22.7% compared to 69.9% for AMIDES. SPECTRA also outperforms five general-purpose LLMs across metrics.
Authors
- Muhammad Shoaib, Ph.D. student, computer science, University of Virginia
- Hare Sudhan Muthusamy, independent researcher
- Tareq Alkhatib, Fortinet
- Wajih Ul Hassan, assistant professor, computer science, University of Virginia
Publication
- Venue: IEEE Symposium on Security and Privacy, 2026
- Date: May 18, 2026