Hello, for some reason Windows does not check amsi.dll in syswow64 which allows for easy dll hijacking.
It will automatically be injected into %50 of processes by Windows Defender itself.
amsi.dll = "anti malware scan interface" - mainly used for detecting malicious scripts (powershell/vbscript...
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.