0xjbb / Amsi-Patch

AMSI ScanBuffer Patch with API Hook poc

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

AMSI Patch via API Hooking

  • It's messy af, its a poc.
  • x64 in Debug mode with Debugger attached doesn't work, don't know why, don't really care.
  • scan.cpp is just to invoke the AmsiScanBuffer function for testing.

About

AMSI ScanBuffer Patch with API Hook poc


Languages

Language:C++ 100.0%