AMSI patching refers to a post-exploitation bypass technique for AMSI in which the attacker patches the AmsiScanBuffer function in memory to force it to return a clean result, effectively disabling script scanning.
AMSI patching
2025-04-02
Recent Posts
Linux Persistence: atd
2025-04-01 DFIR CTF linux persistence at atd
Linux Persistence: SSH
2025-03-29 DFIR CTF SSH hardening hunting persistence linux persistence hunting hardening SSH PAM