Skip to content
KitploitKITPLOIT
도구블로그
Log in
제출
도구블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

피드문의개인정보© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
AntimalwareBlight — Execute PowerShell code at the antimalware-light protection level. | Kitploit
도구/GitHubGitHub/mattifestation/antimalwareblight
ExploitationRed TeamingAdversarial Attack
GitHubmattifestation/antimalwareblight

AntimalwareBlight

Execute PowerShell code at the antimalware-light protection level.

저장소 보기
141192020일 전Kitploit 검토 완료

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
요청한 언어로 콘텐츠를 사용할 수 없습니다. 영어 버전을 표시합니다.

Use this PowerShell module to execute PowerShell code at the antimalware-light protection level. This code was highlighted in the Living Off the Walled Garden: Abusing the Features of the Early Launch Antimalware Ecosystem REcon talk as well as Black Hat USA 2022. This module needs to run elevated. The purpose of this module is to highlight how the antimalware-light protection anti-tampering feature is only as strong as the weakest vendor's ELAM driver.

This is fully-weaponized by the inclusion of the target MSBuild.exe executable and the vulnerable ELAM driver, aswElam.sys that permits its execution at the antimalware-light protection level. These are both legitimate files used as primitives to achieve code execution as a protected process.

Note

In spite of aswElam.sys being an I386 (32-bit) driver, it will work on any processor architecture since it is only used by the kernel to read the ELAM metadata.

Disclosure timeline

Thank you to the Microsoft Defender research team for working with me on this issue! When in doubt, if MSRC won't fix something because it's not a security boundary, the Defender team still likely cares very much!

  • Dec 29, 2021: Initial report to MSRC
  • Jan 11, 2022: MSRC determined that it did not meet the servicing bar since it requires admin
  • Jan 11, 2022: I responded and asked MSRC to ensure that the issue would be passed on the Microsoft Defender for Endpoint team
  • Jun 2022: Released defanged weaponization script and presented findings at Recon and Black Hat USA.
  • Sep 2026: Released fully-weaponized script. Nearly five years is sufficient time to wait.

Usage

Load the module:

Import-Module .\AntimalwareBlight.psm1

View its exported functions:

Get-Command -Module AntimalwareBlight

View help for the module's functions:

Get-Help Invoke-AntimalwareLightCommand -Full
도구 다운로드