Resurrecting an old AMSI Bypass
ID: 26f11dee-57c7-5d85-ba7a-4b9e457b4ded
STIX ID: report--26f11dee-57c7-5d85-ba7a-4b9e457b4ded
Feed Name: SensePost Blog
Threat Score
This blog post demonstrates a proof-of-concept bypass of Windows' Anti-Malware Scan Interface (AMSI) for PowerShell by creating a fake amsi.dll with the expected exports and leveraging DLL search order/DLL hijacking from a user-writable location; the author describes implementation details, ProcMon observations, testing (including required placements of the fake DLL), and mitigation/defense notes (Windows Defender detection and planned PowerShell fixes).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
