S1lkys / PowerShell-Amsi-Hardware-Breakpoints-PoC

Amsi Hardware Break Points .Net 3.5

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Only a PoC

Uses .Net 3.5 to spawn a new Powershell instance using System.Management.Automation namespace. Amsi is bypassed using an hardwarebreakpoint and VEH. Using .NET 3.5 is the latest version where the breakpoint works in the new powershell instance. Therefore the Powershell is very limited here.

About

Amsi Hardware Break Points .Net 3.5


Languages

Language:PowerShell 81.2%Language:C# 18.8%