Joe Desimone
jdez.bsky.social
Joe Desimone
@jdez.bsky.social
Tech Lead, Elastic Security
Bypass AMSI by uninitializing the IActiceScript object (zero ptr at 0x3c8). Slightly modified wscript no longer calls into AMSI.
January 23, 2025 at 2:11 PM