Bypassing AMSI with Powershell
by Vittlesical - Saturday June 1, 2024 at 06:11 PM
#1
Hi guys, today i was scrolling on Github and i  saw a repo talks about AMSI bypass, etc so i took a look at the available scripts there and i picked up the implementation for 64bit, and tried it on my windows VM and it was detected, so i decided to obfuscate it and try to run it, and i was able to bypass the amsi and patching the scan functions.
you can find it here: https://github.com/S3cur3Th1sSh1t/Amsi-B...ile#64-bit


visit: https://learn.microsoft.com/en-us/window...ace-portal
to understand what is AMSI


- this is with the obfuscation techniques implemented below
[Image: Screenshot-from-2024-06-01-10-25-36.png]
as you can see in the photo i was able to patch the scan function and invoke mimikatz


- this is without the obfuscation 
[Image: Screenshot-from-2024-06-01-10-41-35.png]



obfuscation techniques implemented:
- Base64 Encoding
- Simplified Variable Names
- Dynamic Generation


Hidden Content
You must register or login to view this content.


This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: See you on the other side.
Reply
#2
Good share, S3cur3Th1sSh1t always has great stuff.
I can recommend checking him out on youtube aswell, he got hours of content on AV Evasion w/ Powershell amongst other things which are nice to sit through
/@ScurThsSht/videos
Reply
#3
Pretty good share, keep this up
Reply
#4
(Jun 01, 2024, 06:22 PM)None Wrote: Good share, S3cur3Th1sSh1t always has great stuff.
I can recommend checking him out on youtube aswell, he got hours of content on AV Evasion w/ Powershell amongst other things which are nice to sit through
/@ScurThsSht/videos

he has great stuff indeed
i checked him most of the techniques he explain detected thats why i modified the pwsh script because a lot of kids use it on their vm with cloud protections enabled and everytime they execute it it sends samples to microsoft until they were able to make an update detects it.

(Jun 01, 2024, 06:29 PM)xzin0vich Wrote: Pretty good share, keep this up

will do, thanks!

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: See you on the other side.
Reply
#5
Great stuff ,let me see the content.

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching | https://breachforums.rs/Forum-Ban-Appeals if you feel this is incorrect.
Reply
#6
i was playing with that one also
Reply
#7
(Jun 01, 2024, 06:11 PM)SilentMastermind Wrote: Hi guys, today i was scrolling on Github and i  saw a repo talks about AMSI bypass, etc so i took a look at the available scripts there and i picked up the implementation for 64bit, and tried it on my windows VM and it was detected, so i decided to obfuscate it and try to run it, and i was able to bypass the amsi and patching the scan functions.
you can find it here: https://github.com/S3cur3Th1sSh1t/Amsi-B...ile#64-bit


visit: https://learn.microsoft.com/en-us/window...ace-portal
to understand what is AMSI


- this is with the obfuscation techniques implemented below
[Image: Screenshot-from-2024-06-01-10-25-36.png]
as you can see in the photo i was able to patch the scan function and invoke mimikatz


- this is without the obfuscation 
[Image: Screenshot-from-2024-06-01-10-41-35.png]



obfuscation techniques implemented:
- Base64 Encoding
- Simplified Variable Names
- Dynamic Generation

This tools is very nice thanks for share

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you feel this is incorrect.
Reply
#8
thanks for the share
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  [ LIST ] 5 FREE STEALERS WITH PROS/CONS elix 393 15,873 9 hours ago
Last Post: subrsp
  Sektor7 - Malware Development Advanced - Vol.1 Sh4d0w1X 427 44,761 Yesterday, 07:45 AM
Last Post: Letmein1
  Bypass Cookies Encryption | Working FrancisMDouble 8 1,159 May 03, 2026, 12:43 AM
Last Post: 0x0xGunger998
  Malware On Steroids 0neSh0t 348 24,569 May 03, 2026, 12:34 AM
Last Post: 0x0xGunger998
  Malware Development MD MZ E Book Mandala 51 2,155 May 03, 2026, 12:28 AM
Last Post: 0x0xGunger998

Forum Jump:


 Users browsing this forum: 1 Guest(s)