> For the complete documentation index, see [llms.txt](https://windows.dfirhandbook.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://windows.dfirhandbook.com/windows-dfir-and-mittr/defense-evasion.md).

# Defense Evasion

* T1562: Impair Defenses
* T1140: Deobfuscate/Decode Files or Information
* T1027: Obfuscated Files or Information
* T1497: Virtualization/Sandbox Evasion
* T1070: Indicator Removal on Host
* T1036: Masquerading
* T1218: Signed Binary Proxy Execution
* T1574: Hijack Execution Flow
* T1553: Subvert Trust Controls
* T1480: Execution Guardrails
* T1499: Endpoint Denial of Service
