AMSI

PowerShell Downgrade

powershell -version 2

Base64 Encoding

This technique prevents AMSI scanning capability for the current process by setting the “amsiInitFailed” flag.

Memory Patching

C# Version

Powershell Version

Last updated