Hacking Tools

AMSI-Bypass-HWBP : A Tool For Evading AMSI Detection

AMSI (Antimalware Scan Interface) is a Windows feature designed to help protect systems from malware by scanning scripts and files for malicious content.

However, attackers often seek to bypass AMSI to execute malicious scripts undetected. One such tool for bypassing AMSI is AMSI-Bypass-HWBP, which utilizes a small debugger to manipulate the behavior of AMSI.

Functionality Of AMSI-Bypass-HWBP

AMSI-Bypass-HWBP operates by creating a new instance of powershell.exe or attaching to an existing one.

It then sets a hardware breakpoint at the address of the AmsiScanBuffer() function within amsi.dll. This function is crucial as it scans buffers for malware.

Once the breakpoint is triggered, the tool modifies the third parameter of AmsiScanBuffer(), which is the length of the buffer to be scanned, stored in the R8 register.

By setting this length to 1, the tool ensures that AmsiScanBuffer() only scans a single byte of the buffer.

This manipulation results in AMSI_RESULT_CLEAN, indicating that the scanned content is clean, effectively bypassing AMSI’s detection.

  • Setting Hardware Breakpoints: The tool uses Windows API functions to set a hardware breakpoint on AmsiScanBuffer(). This allows it to intercept and modify the function’s behavior at runtime.
  • Modifying the Length Parameter: By changing the length parameter to 1, the tool limits the scan to a single byte, which is unlikely to trigger any malware detection.
  • Result: The manipulation leads to a clean scan result, allowing malicious scripts to execute without being flagged by AMSI.

The development of AMSI-Bypass-HWBP was influenced by Justin Seitz’s book, “Gray Hat Python”, which provides insights into using Windows API functions for debugging processes.

This knowledge is crucial for understanding how to interact with and manipulate system-level functions like those in AMSI.

In summary, AMSI-Bypass-HWBP is a sophisticated tool that exploits the behavior of AMSI by manipulating its scanning function, allowing attackers to execute scripts without detection.

Its development highlights the ongoing cat-and-mouse game between security measures and evasion techniques in the cybersecurity landscape.

Varshini

Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies.

Recent Posts

groupdel Command in Linux: Remove a Group and Audit Files

The groupdel command in Linux removes a group from the system. It deletes the group's entry from /etc/group and /etc/gshadow,…

8 hours ago

wc Command in Linux: Count Lines, Words, Characters, and Bytes

The wc command in Linux counts lines, words, characters, and bytes in files or standard input. It…

8 hours ago

top Command in Linux: Monitor Processes and Resource Usage

The top command in Linux provides a real-time view of running processes and system resource usage. From…

8 hours ago

usermod Command in Linux: Modify User Accounts and Groups

The usermod command in Linux modifies existing user account attributes. You can use it to manage group…

8 hours ago

sort Command in Linux: Sort Text, Numbers, Columns, and More

The sort command in Linux reads lines from files or standard input and writes them to standard…

1 day ago

wall Command in Linux: Broadcast Messages to Logged-In Users

The wall command in Linux sends a message to the terminals of all currently logged-in users. The…

1 day ago