• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    AMSI Bypass via In-Memory Patching Before Payload Retrieval

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Ibrahim Saud@tektrix
    •updated 20 days ago•1•0•2

    This rule detects attempts by a process (specifically targeting PowerShell or .NET loaders) to tamper with Windows Antimalware Scan Interface (AMSI) components in memory. It correlates EDR or Sysmon events (process access, module loads) targeting 'amsi.dll' or involving specific AMSI API strings like 'AmsiScanBuffer' or 'AmsiInitFailed' with potential malicious loader activity.

    Splunk (SPL)

    Tags

    T1685 - Disable or Modify ToolsT1620 - Reflective Code LoadingTA0005 - StealthProcess TamperingProcess Module LoadProcess AccessWindowsWindows SysmonCrowdstrike Falcon EDRSentinelone EDRWindows Eventlog Securityspl

    Found in

    • LausivLoader Analysis: Multi-Stage Infection via Environment VariablesLast updated 21 days ago
    • LausivLoader Analysis: Multi-Stage Infection via Environment VariablesLast updated 21 days ago
    • LausivLoader Analysis: Multi-Stage Infection via Environment VariablesLast updated 21 days ago
    • LausivLoader Analysis: Multi-Stage Infection via Environment VariablesLast updated 21 days ago
    • LausivLoader Analysis: Multi-Stage Infection via Environment VariablesLast updated 21 days ago

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?