- It's messy af, its a poc.
- x64 in Debug mode with Debugger attached doesn't work, don't know why, don't really care.
- scan.cpp is just to invoke the AmsiScanBuffer function for testing.
AMSI ScanBuffer Patch with API Hook poc
AMSI ScanBuffer Patch with API Hook poc