This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
AMSI Disabled via Registry Modification
Original Source:
[Sigma source]
Title:
AMSI Disabled via Registry Modification
Status:
experimental
Description:
Detects attempts to disable AMSI (Anti-Malware Scan Interface) by modifying the AmsiEnable registry value. Anti-Malware Scan Interface (AMSI) is a security feature in Windows that allows applications and services to integrate with anti-malware products for enhanced protection against malicious content. Adversaries may attempt to disable AMSI to evade detection by security software, allowing them to execute malicious scripts or code without being scanned.
References:
-https://mostafayahiax.medium.com/hunting-for-amsi-bypassing-methods-9886dda0bf9d
-https://docs.microsoft.com/en-us/windows/win32/amsi/antimalware-scan-interface-portal
-https://www.mdsec.co.uk/2019/02/macros-and-more-with-sharpshooter-v2-0/
Author:
Swachchhanda Shrawan Poudel (Nextron Systems)
Date:
2025-12-25
modified:
None
Tags:
-'attack.defense-impairment'
-'attack.t1685'
Logsource:
category: registry_set
product: windows
Detection:
selection:
TargetObject|endswith
:
'\Software\Microsoft\Windows Script\Settings\AmsiEnable'
Details
:
'DWORD (0x00000000)'
condition
:
selection
Falsepositives:
-Unlikely
Level:
high