Skip to content
KitploitKITPLOIT
工具博客
Log in
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
AntimalwareBlight — Execute PowerShell code at the antimalware-light protection level. | Kitploit
工具/GitHubGitHub/mattifestation/antimalwareblight
ExploitationRed TeamingAdversarial Attack
GitHubmattifestation/antimalwareblight

AntimalwareBlight

Execute PowerShell code at the antimalware-light protection level.

查看仓库
141192019天前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
内容在请求的语言中不可用。显示英文版本。

Use this PowerShell module to execute PowerShell code at the antimalware-light protection level. This code was highlighted in the Living Off the Walled Garden: Abusing the Features of the Early Launch Antimalware Ecosystem REcon talk as well as Black Hat USA 2022. This module needs to run elevated. The purpose of this module is to highlight how the antimalware-light protection anti-tampering feature is only as strong as the weakest vendor's ELAM driver.

This is fully-weaponized by the inclusion of the target MSBuild.exe executable and the vulnerable ELAM driver, aswElam.sys that permits its execution at the antimalware-light protection level. These are both legitimate files used as primitives to achieve code execution as a protected process.

Note

In spite of aswElam.sys being an I386 (32-bit) driver, it will work on any processor architecture since it is only used by the kernel to read the ELAM metadata.

Disclosure timeline

Thank you to the Microsoft Defender research team for working with me on this issue! When in doubt, if MSRC won't fix something because it's not a security boundary, the Defender team still likely cares very much!

  • Dec 29, 2021: Initial report to MSRC
  • Jan 11, 2022: MSRC determined that it did not meet the servicing bar since it requires admin
  • Jan 11, 2022: I responded and asked MSRC to ensure that the issue would be passed on the Microsoft Defender for Endpoint team
  • Jun 2022: Released defanged weaponization script and presented findings at Recon and Black Hat USA.
  • Sep 2026: Released fully-weaponized script. Nearly five years is sufficient time to wait.

Usage

Load the module:

Import-Module .\AntimalwareBlight.psm1

View its exported functions:

Get-Command -Module AntimalwareBlight

View help for the module's functions:

Get-Help Invoke-AntimalwareLightCommand -Full
下载工具