logo

Resurrecting an old AMSI Bypass

ID: 26f11dee-57c7-5d85-ba7a-4b9e457b4ded

STIX ID: report--26f11dee-57c7-5d85-ba7a-4b9e457b4ded

Feed Name: SensePost Blog

Threat Score
50/100

Date Published: 2020-06-24

Date Updated: 2026-04-30

...
...

This blog post demonstrates a proof-of-concept bypass of Windows' Anti-Malware Scan Interface (AMSI) for PowerShell by creating a fake amsi.dll with the expected exports and leveraging DLL search order/DLL hijacking from a user-writable location; the author describes implementation details, ProcMon observations, testing (including required placements of the fake DLL), and mitigation/defense notes (Windows Defender detection and planned PowerShell fixes).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.