.. / AMSI-Bypass-Jscript_amsienable
Star

In this Amsi Bypass it sets the HKCU\Software\Microsoft\Windows Script\Settings\AmsiEnable registry key to 0 and run the evil script. Add the code at the beginning of your evil Jscript file to turn off the AMSI.

Command Reference:

Registry key: HKCU\\Software\\Microsoft\\Windows Script\\Settings\\AmsiEnable

-e:  option indicates that the specified script file will be processed by jscript.dll (GUID)

GUID: F414C262-6AC0-11CF-B6D1-00AA00BBBB58
Command: Copy Extra code: Copy References:

https://ppn.snovvcrash.rocks/pentest/infrastructure/ad/av-edr-evasion/amsi-bypass#jscript