SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsScripting languages are increasingly dominant malware vectors that often employ layered obfuscation techniques to slow down manual analysis by reverse engineers and to prevent pattern recognition. Existing deobfuscators are often developed for specific encoding mechanisms or programming languages, resulting in complex analysis pipelines that require multiple tools or techniques to analyze samples fully. DeScrypt is a multi-tool deobfuscation orchestration framework that integrates native decoders and available tools to automatically select and invoke plausible decoding techniques, including chains that span multiple languages within a single sample.
This paper evaluates its effectiveness on 1,000 malicious samples (500 JS / 500 PS) and compares the results with 200 benign samples. DeScrypt invoked at least one tool in 75.9% of samples, with 33.9% achieving a clean terminal payload and a 1% false-positive rate for benign samples. The orchestration extends coverage beyond a single-engine tool and has shown greater effectiveness for JavaScript samples than for PowerShell samples. A majority of samples that scored zero had nonetheless been unpacked at least once, highlighting the decoupling of effective deobfuscation from the detection of malicious scripts.



















