AMSI Patch
Patches AmsiScanBuffer in the current process so every scan returns clean,
disabling in-process AMSI inspection of scripts and .NET content.
Metadata
Section titled “Metadata”| ATT&CK | T1562.001 (Impair Defenses: Disable or Modify Tools) |
| Stability | Stable |
| Category | Preparation |
| YAML key | patch_amsi |
| Introduced in | Phase 7 |
What it does
Section titled “What it does”Patches AmsiScanBuffer in the current process so it always returns S_OK (clean), disabling AMSI for any code that invokes it in-process: PowerShell, WMI, VBScript, JScript, and .NET assembly loading. It does not run the payload; it only modifies process state, which is why it is a Preparation technique.
YAML parameters
Section titled “YAML parameters”None.
YAML example
Section titled “YAML example”runtime: - technique: patch_amsiHow it works
Section titled “How it works”sequenceDiagram
participant L as Loader
participant A as amsi.dll
L->>A: LoadLibraryA(amsi.dll)
L->>A: GetProcAddress(AmsiScanBuffer)
L->>A: nt_protect_vm(RWX)
L->>A: write 29 C0 C3 (sub eax,eax; ret)
L->>A: restore original protection
Note over L,A: AmsiScanBuffer now returns S_OK
1. Resolve the target export
Section titled “1. Resolve the target export”- Load
amsi.dll(LoadLibraryA, a no-op if already loaded). - Resolve
AmsiScanBufferwithGetProcAddress.
2. Overwrite the prologue
Section titled “2. Overwrite the prologue”- Make the first three bytes of
AmsiScanBufferwritable (nt_protect_vm→PAGE_EXECUTE_READWRITE). - Write
sub eax, eax; ret(29 C0 C3): zero EAX (S_OK) and return. - Restore the original page protection.
If amsi.dll cannot be loaded (e.g. AMSI is unavailable), the preparation
returns a clear error and the pipeline fails with a useful message.
What it evades
Section titled “What it evades”- AMSI scanning of scripts and .NET assemblies in the current process.
What detects it
Section titled “What detects it”- Hooks on
NtProtectVirtualMemorytargetingPAGE_EXECUTE_READWRITEoveramsi.dll. - ETW-TI (
Microsoft-Windows-Threat-Intelligence) on suspicious memory writes. - Memory scanning / YARA looking for the
29 C0 C3(orB8 57 00 07 80 C3) patch at the start ofAmsiScanBuffer. Signatures vary per EDR. - AMSI event log entries if the patch is applied only partially or too late.
Measurements
Section titled “Measurements”- Pending — needs a .NET or script payload that actually invokes AMSI.
Implementation notes
Section titled “Implementation notes”- The patch
29 C0 C3is chosen because it is the shortest valid stub (sub eax, eax; ret). An alternative ismov eax, 0x80070057; ret(B8 57 00 07 80 C3), which returnsE_INVALIDARG;29 C0 C3is shorter. - Only affects the current process. If the payload runs in another process (e.g. process hollowing), that process’s AMSI is not patched here; doing so will require a parameter on the corresponding execution technique.
amsi.dllandAmsiScanBufferare reconstructed at runtime throughStringsConfig(render_fragment), so they never appear in cleartext in.rdata. The page protection change goes through the syscall layer’snt_protect_vm, somode: indirectremoves theVirtualProtectimport;LoadLibraryA/GetProcAddressstay Win32 (as in every technique).
References
Section titled “References”- AMSI bypass / patch techniques (e.g. the classic
AmsiScanBufferbyte patch). - MITRE ATT&CK T1562.001 — Impair Defenses: Disable or Modify Tools.