Skip to content
← LibraryTechnique entry
AMSI-PATCHDefense Evasion

AMSI In-Memory Patch

Patch AmsiScanBuffer in amsi.dll memory to return clean — PowerShell / VBA / .NET runtime emits content unscanned.

§ Where this technique fits

AMSI-PATCH is catalogued under the Defense Evasion tactic of the offensive-security kill-chain. It appears in 1 approved dossier in the registry, typically at step 2 on average.

§ Dossiers chaining this technique

§ What commonly comes next

  1. 01
    ETW Event-Tracing Patch
    ETW-PATCH · Defense Evasion
    seen 1×