
Execute PowerShell code at the antimalware-light protection level.
Use this PowerShell module to execute PowerShell code at the antimalware-light protection level. This code was highlighted in the Living Off the Walled Garden: Abusing the Features of the Early Launch Antimalware Ecosystem REcon talk as well as Black Hat USA 2022. This module needs to run elevated. The purpose of this module is to highlight how the antimalware-light protection anti-tampering feature is only as strong as the weakest vendor's ELAM driver.
This is fully-weaponized by the inclusion of the target MSBuild.exe executable and the vulnerable ELAM driver, aswElam.sys that permits its execution at the antimalware-light protection level. These are both legitimate files used as primitives to achieve code execution as a protected process.
In spite of aswElam.sys being an I386 (32-bit) driver, it will work on any processor architecture since it is only used by the kernel to read the ELAM metadata.
Thank you to the Microsoft Defender research team for working with me on this issue! When in doubt, if MSRC won't fix something because it's not a security boundary, the Defender team still likely cares very much!
Load the module:
Import-Module .\AntimalwareBlight.psm1
View its exported functions:
Get-Command -Module AntimalwareBlight
View help for the module's functions:
Get-Help Invoke-AntimalwareLightCommand -Full