حال به توضیح قسمتی از این تکنیک اشاره میکنیم:
There is a low detection surface:
statically: because the code profile is so short and it is hard to apply a signature on any part of the common .NET functionality used
dynmically: because of the lack of hooked win32 API calls
Because we are modifying JIT/IL memory which is hard for AV/EDR to monitor or has not been monitored at this point by a lot of vendors
! For some security products, modify method M to pass in empty argument string c.
! For CSHARP example, private static int M(string c, string s) { c = ""; return 1; }
! For POWERSHELL example, class TrollAMSI{static [int] M([string]$c, [string]$s){ $c = ""; return 1}}
! Refer to TrollAMSIdotnet for amsi bypass for Assembly.Load()
Benefits
No P/Invoke or win32 API calls used such as VirtualProtect hence more opsec safe
No amsi.dll patching or byte patching for that matter
در ادامه نکاتی را برای رعایت OpSec میتوان اشاره کرد:
STATIC: obfuscate "AmsiUtils" and "ScanContent" maybe?
DYNAMIC: Nothing much really. Note that Add-Type method will leave disk artifacts, whereas hosting the compiled DLL on a webserver and using Load() is completely in memory
https://github.com/cybersectroll/TrollAMSI/tree/main
#RedTeam #AMSI
@securation