EmpireProject / Empire

Empire is a PowerShell and Python post-exploitation agent.
http://www.powershellempire.com/
BSD 3-Clause "New" or "Revised" License
7.39k stars 2.81k forks source link

Add rastamouse AMSI bypass #1290

Closed phra closed 5 years ago

phra commented 5 years ago

https://rastamouse.me/2018/10/amsiscanbuffer-bypass-part-1/ https://rastamouse.me/2018/10/amsiscanbuffer-bypass-part-2/ https://rastamouse.me/2018/11/amsiscanbuffer-bypass-part-3/

mr64bit commented 5 years ago

PR merged, closing issue.