Skip to main content

Tradecraft Improvement 3 - AMSI Evasions 1 - Reverse Engineering AMSI

Pre-requisites Basic understanding of Windows internals Some knowledge about PowerShell Basic knowledge about malwares Basic C/C++ knowledge Introduction to AMSI There are already a number of blogs and sources dedicated to the evasion of Microsoft’s Antimalware Scan Interface aka AMSI. But I wanted to write a blog which would encompass certain important tips and tricks that would help you improve your own bypasses and would give you some knowledge and understanding of AMSI to look for more bypasses as well.