Getting PowerShell Empire Past Windows Defender
ID: 6d305483-4793-5c0f-8e0d-72a1f15f82d1
STIX ID: report--6d305483-4793-5c0f-8e0d-72a1f15f82d1
Feed Name: Black Hills Infosec Blog
This guest blog post explains how an operator can use SharpSploit and SharpGen to evade Windows Defender by leveraging an AMSI bypass and packaging PowerShell Empire launchers into .NET executables; it includes build commands, resource/config edits (disabling PowerKatz), running a Base64 Empire launcher, and operational recommendations for HTTPS, valid certificates, domain selection, and application whitelisting bypasses. The post also notes that Windows Defender added detection for this AMSI tampering (AmsiTamper.A).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
