logo

Getting PowerShell Empire Past Windows Defender

ID: 6d305483-4793-5c0f-8e0d-72a1f15f82d1

STIX ID: report--6d305483-4793-5c0f-8e0d-72a1f15f82d1

Feed Name: Black Hills Infosec Blog

Threat Score
65/100

Date Published: 2019-02-15

Date Updated: 2026-04-27

Author: BHIS

...
...

This guest blog post explains how an operator can use SharpSploit and SharpGen to evade Windows Defender by leveraging an AMSI bypass and packaging PowerShell Empire launchers into .NET executables; it includes build commands, resource/config edits (disabling PowerKatz), running a Base64 Empire launcher, and operational recommendations for HTTPS, valid certificates, domain selection, and application whitelisting bypasses. The post also notes that Windows Defender added detection for this AMSI tampering (AmsiTamper.A).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.