← All Lessons
Premium

TechniqueActive Directory

Command and Script Obfuscation

Command and script obfuscation rewrites an attacker's commands so they run exactly the same but no longer match what a defender's tools are watching for. This lesson explains why changing the form of a command defeats signature-based detection while its behavior stays identical, what the tactic actually buys an attacker, where controls like AMSI still catch it, and how to communicate the risk in interviews, reports, and stakeholder conversations.

Sign in or upgrade to unlock the full premium library.

What you'll learn

  • Command and script obfuscation
  • Signature-based detection
  • Encoded command
  • AMSI (Antimalware Scan Interface)
  • Runtime reassembly
  • Behavior versus representation

What premium includes

  • All 78 lessons: AD techniques, professional skills, each with interview answers and study kits
  • Complete study kit for every lesson: quizzes, flashcards, and briefs
  • Every learning track with full structured progression
  • All 12 attack paths: full compromise walkthroughs for interviews and reports
  • New lessons and attack paths added regularly

Continue with free content

Command and Script Obfuscation — ExplainTheHack