Bypassing AMSI with Powershell
by Vittlesical - Saturday June 1, 2024 at 06:11 PM
#1
Hi guys, today i was scrolling on Github and i  saw a repo talks about AMSI bypass, etc so i took a look at the available scripts there and i picked up the implementation for 64bit, and tried it on my windows VM and it was detected, so i decided to obfuscate it and try to run it, and i was able to bypass the amsi and patching the scan functions.
you can find it here: https://github.com/S3cur3Th1sSh1t/Amsi-B...ile#64-bit


visit: https://learn.microsoft.com/en-us/window...ace-portal
to understand what is AMSI


- this is with the obfuscation techniques implemented below
[Image: Screenshot-from-2024-06-01-10-25-36.png]
as you can see in the photo i was able to patch the scan function and invoke mimikatz


- this is without the obfuscation 
[Image: Screenshot-from-2024-06-01-10-41-35.png]



obfuscation techniques implemented:
- Base64 Encoding
- Simplified Variable Names
- Dynamic Generation


Hidden Content
You must register or login to view this content.


This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: See you on the other side.
Reply
#2
Good share, S3cur3Th1sSh1t always has great stuff.
I can recommend checking him out on youtube aswell, he got hours of content on AV Evasion w/ Powershell amongst other things which are nice to sit through
/@ScurThsSht/videos
Reply
#3
Pretty good share, keep this up
Reply
#4
(Jun 01, 2024, 06:22 PM)None Wrote: Good share, S3cur3Th1sSh1t always has great stuff.
I can recommend checking him out on youtube aswell, he got hours of content on AV Evasion w/ Powershell amongst other things which are nice to sit through
/@ScurThsSht/videos

he has great stuff indeed
i checked him most of the techniques he explain detected thats why i modified the pwsh script because a lot of kids use it on their vm with cloud protections enabled and everytime they execute it it sends samples to microsoft until they were able to make an update detects it.

(Jun 01, 2024, 06:29 PM)xzin0vich Wrote: Pretty good share, keep this up

will do, thanks!

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: See you on the other side.
Reply
#5
Great stuff ,let me see the content.

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching | https://breachforums.rs/Forum-Ban-Appeals if you feel this is incorrect.
Reply
#6
i was playing with that one also
Reply
#7
(Jun 01, 2024, 06:11 PM)SilentMastermind Wrote: Hi guys, today i was scrolling on Github and i  saw a repo talks about AMSI bypass, etc so i took a look at the available scripts there and i picked up the implementation for 64bit, and tried it on my windows VM and it was detected, so i decided to obfuscate it and try to run it, and i was able to bypass the amsi and patching the scan functions.
you can find it here: https://github.com/S3cur3Th1sSh1t/Amsi-B...ile#64-bit


visit: https://learn.microsoft.com/en-us/window...ace-portal
to understand what is AMSI


- this is with the obfuscation techniques implemented below
[Image: Screenshot-from-2024-06-01-10-25-36.png]
as you can see in the photo i was able to patch the scan function and invoke mimikatz


- this is without the obfuscation 
[Image: Screenshot-from-2024-06-01-10-41-35.png]



obfuscation techniques implemented:
- Base64 Encoding
- Simplified Variable Names
- Dynamic Generation

This tools is very nice thanks for share

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you feel this is incorrect.
Reply
#8
thanks for the share
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  Sektor7 - Malware Development Advanced - Vol.1 Sh4d0w1X 433 45,446 5 hours ago
Last Post: Bread32Bit
  Xordium stealer for Pulsar v2.4.5 nullvex 28 1,242 6 hours ago
Last Post: pddemerde
  Phishing Platform with 2FA bypass support Loki 141 22,482 6 hours ago
Last Post: pddemerde
  Bypass Cookies Encryption | Working FrancisMDouble 9 1,201 7 hours ago
Last Post: Breacher_Lokidas
  [Sektor7] Full Recent Course Spearr 34 1,114 9 hours ago
Last Post: OverclockX

Forum Jump:


 Users browsing this forum: 1 Guest(s)