I-Am-Jakoby / Flipper-Zero-BadUSB

Repository for my flipper zero badUSB payloads. Now almost entirely plug and play.

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

AMSI bypass

HughMungis opened this issue · comments

seems like a lot of payloads are getting caught by AMSI. is it possible to have a "stage 0" where the script downloads your payload, applies an AMSI bypass and/or obfuscation, and then runs the payload? I've been trying to think of a way to do this non-deterministically so that no two executions would look the same but my knowledge of powershell isn't that good (yet lol).