amsi: how windows 10 plans to stop script-based … · black hat usa amsi: how windows 10 plans to...

26
1

Upload: buinhu

Post on 19-Aug-2018

220 views

Category:

Documents


0 download

TRANSCRIPT

1

2

3

4

5

https://msdn.microsoft.com/en-us/library/windows/desktop/dn889587(v=vs.85).aspxhttps://blogs.technet.microsoft.com/poshchap/2015/10/16/security-focus-defending-powershell-with-the-anti-malware-scan-interface-amsi/https://blogs.technet.microsoft.com/mmpc/2015/06/09/windows-10-to-offer-application-developers-new-malware-defenses/

6

7

https://github.com/Ben0xA/nps

8

All demonstrations on 64-bit Windows 10 build 10586

9

10

PowerShell code and scripts can be executed without using PowerShell.exe. Please see:https://github.com/leechristensen/UnmanagedPowerShellhttps://github.com/Ben0xA/npshttps://github.com/PowerShellEmpire/PowerTools/tree/master/PowerPick

Interesting methods to bypass Application whitelistinghttp://subt0x10.blogspot.in/2016/04/bypass-application-whitelisting-script.htmlhttp://subt0x10.blogspot.in/2015/08/application-whitelisting-bypasses-101.htmlhttps://raw.githubusercontent.com/subTee/ApplicationWhitelistBypassTechniques/master/TheList.txthttp://www.labofapenetrationtester.com/2016/05/practical-use-of-javascript-and-com-for-pentesting.html

11

12

13

14

15

16

17

18

19

20

Source: https://twitter.com/mattifestation/status/735261176745988096

21

Source: http://cn33liz.blogspot.com/2016/05/bypassing-amsi-using-powershell-5-dll.html

22

23

24

25

26