Catch Me If You Can: Detector-Resistant Evasion via Semantics-Preserving Command Re-Realization

SPECTRA — Semantics Preserving Command Transformations for Rule Avoidance

Abstract

Red teams require robust evasion techniques to test Security Information and Event Management (SIEM) detection rules, yet existing approaches are (1) manual, (2) rely on string-level obfuscations (such as encoding schemes and quoting tricks) that are easily reversed by de-obfuscators, and (3) provide limited rule coverage. This leaves unexplored semantic-preserving evasions that achieve identical effects through different utilities, preventing assessment of whether rules detect attack intent or merely surface patterns.

We present SPECTRA, an automated evasion generator that preserves attack effects while transforming command-line realization through functionally equivalent utilities and argument structures. By reasoning over semantic representations rather than syntactic patterns, SPECTRA automatically generates more durable and effective evasions. On Windows Sigma process_creation rules, SPECTRA achieves 72.9% rule coverage compared to 37.6% for AMIDES (the state-of-the-art method), with only 4.5% of evasions reversed by de-obfuscators versus 78.1% for AMIDES (17.4 times more resistant). When evaluated against the state-of-the-art evasion detector at its zero-false-positive operating point, SPECTRA achieves a detection rate of only 22.7% compared to 69.9% for AMIDES. SPECTRA also outperforms five general-purpose LLMs across various metrics.

Key Results

72.9%
Rule Coverage
(vs. 37.6% AMIDES)
4.5%
De-obfuscation Rate
(vs. 78.1% AMIDES)
22.7%
Detection Rate
(vs. 69.9% AMIDES)
97.2%
Windows Conformance
(valid commands)

System Overview

SPECTRA takes two inputs—a seed corpus of Sigma rules paired with triggering commands, and a reference corpus of documented system utilities—and processes them through four components:

1

Rule Effect Extractor

Extracts semantic effects from seed commands using a BiLSTM-CRF tagger and trained classifier. Builds a seed effect graph and identifies rule literals to avoid.

2

Reference Processor

Analyzes documented utilities to discover which functions realize which effects. Builds reference effect graphs and argument schemas from documentation.

3

Effect Matching Engine

Maps seed effect graphs to candidate utilities using composite effect keys. Enforces multiplicity agreement, chain-shape matching, and cross-binary preference.

4

Evasion Synthesizer

Selects a candidate utility, synthesizes concrete arguments under schema constraints, and validates the result against the avoid set and effect graph.

Why SPECTRA Is Different

Semantic vs. Syntactic

Prior approaches obfuscate strings (Base64, quoting, caret insertion). SPECTRA replaces procedures—swapping utilities and argument structures while preserving the attack’s effects. This makes evasions orthogonal to de-obfuscation tools.

Fully Automated

Unlike AMIDES which requires manual analysis per rule, SPECTRA is fully automated: it trains a shared extractor, builds effect graphs from cached documentation, and fills arguments under a fixed validator with no per-rule tuning.

Low Collateral Alerting

SPECTRA produces only 31 total collateral alerts (0.149 per fully evaded rule) compared to 79 for AMIDES. Evasions don’t just dodge the target rule—they avoid triggering other rules in the set.

Code & Artifacts

We present SPECTRA as a robustness-evaluation tool for authorized security testing. Rather than broadly releasing the full artifact, we provide access through a request form and review requests case by case based on the requester's stated use. Requesters will need to affirm their institutional affiliation, describe the intended use case, and confirm that testing will be conducted only against systems they are authorized to evaluate.

Request Access

Citation

@inproceedings{shoaib2026spectra, title = {Catch Me If You Can: Detector-Resistant Evasion via Semantics-Preserving Command Re-Realization}, author = {Shoaib, Muhammad and Muthusamy, Hare Sudhan and Alkhatib, Tareq and Hassan, Wajih Ul}, booktitle = {IEEE Symposium on Security and Privacy (S\&P)}, year = {2026}, publisher = {IEEE}, }