{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata — refreshed continuously.","feed_url":"https://feed.craftedsignal.io/tags/amsi-bypass/","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cves":[],"_cs_exploited":false,"_cs_products":["Microsoft Defender XDR","SentinelOne Cloud Funnel","Crowdstrike FDR","Elastic Endgame","Elastic Defend"],"_cs_severities":["high"],"_cs_tags":["defense-evasion","amsi-bypass","dll-hijacking","windows"],"_cs_type":"advisory","_cs_vendors":["Microsoft","SentinelOne","CrowdStrike","Elastic"],"content_html":"\u003cp\u003eThe Antimalware Scan Interface (AMSI) is a Windows interface that allows applications and services to integrate with antimalware products. Attackers may attempt to bypass AMSI to execute malicious code without detection. This detection identifies the creation of the AMSI DLL (\u003ccode\u003eamsi.dll\u003c/code\u003e) in unusual locations, which is a common technique used to load a rogue AMSI module instead of the legitimate one. This technique can be used to evade detection by security products that rely on AMSI for scanning potentially malicious scripts and code. The rule is designed to work with data from Winlogbeat, Elastic Endpoint, Sysmon, Endgame, SentinelOne Cloud Funnel, Microsoft Defender XDR, and Crowdstrike.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker gains initial access to a Windows system through various means (e.g., phishing, exploit).\u003c/li\u003e\n\u003cli\u003eThe attacker determines the location of the legitimate \u003ccode\u003eamsi.dll\u003c/code\u003e file.\u003c/li\u003e\n\u003cli\u003eThe attacker identifies a writable directory where a malicious \u003ccode\u003eamsi.dll\u003c/code\u003e can be placed. This location must be in the search order of applications that use AMSI, such as PowerShell or other scripting hosts.\u003c/li\u003e\n\u003cli\u003eThe attacker copies or creates a malicious \u003ccode\u003eamsi.dll\u003c/code\u003e in the identified location. This rogue DLL is designed to bypass or disable AMSI functionality.\u003c/li\u003e\n\u003cli\u003eA process like PowerShell or another scripting host is launched. Because the malicious \u003ccode\u003eamsi.dll\u003c/code\u003e is in a higher-priority directory, it is loaded instead of the legitimate AMSI library.\u003c/li\u003e\n\u003cli\u003eThe launched process executes malicious code (e.g., PowerShell script).\u003c/li\u003e\n\u003cli\u003eBecause the rogue \u003ccode\u003eamsi.dll\u003c/code\u003e is loaded, AMSI scans are bypassed, allowing the malicious code to execute without detection.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eA successful AMSI bypass can allow attackers to execute malicious code, such as malware, scripts, or exploits, without detection by antimalware products. This can lead to system compromise, data theft, or other malicious activities. The impact can range from a single compromised endpoint to a wider breach of an organization\u0026rsquo;s network.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eEnable file creation monitoring with Sysmon or Elastic Defend to detect the creation of files, specifically DLLs, in unusual locations.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rule \u0026ldquo;Suspicious Antimalware Scan Interface DLL Creation\u0026rdquo; to your SIEM to detect the creation of \u003ccode\u003eamsi.dll\u003c/code\u003e in non-standard paths. Tune the rule for your environment.\u003c/li\u003e\n\u003cli\u003eInvestigate any alerts generated by the Sigma rule by examining the parent process, file path, and user context to determine if the activity is malicious.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2024-01-03T15:00:00Z","date_published":"2024-01-03T15:00:00Z","id":"/briefs/2024-01-amsi-dll-hijack/","summary":"An adversary may attempt to bypass AMSI by creating a rogue AMSI DLL in an unusual location to evade detection.","title":"Suspicious Antimalware Scan Interface DLL Creation","url":"https://feed.craftedsignal.io/briefs/2024-01-amsi-dll-hijack/"}],"language":"en","title":"CraftedSignal Threat Feed — Amsi-Bypass","version":"https://jsonfeed.org/version/1.1"}