Public offensive tooling and research continue to show how attackers can weaken PowerShell defenses by bypassing AMSI, suppressing Script Block Logging, and evading Constrained Language Mode. MDSec documented several methods, including flipping the private .NET flag System.Management.Automation.AmsiUtils.amsiInitFailed, patching amsi.dll in memory, forcing AmsiOpenSession failures, altering cached Group Policy settings to disable logging, and clearing PowerShell's suspicious signature list to reduce forced logging. The techniques were later operationalized in tools such as Stracciatella, a C# runspace launcher that executes PowerShell while attempting to disable AMSI, ETW, and logging at startup, supports encoded input and named-pipe command delivery, and was promoted for use with frameworks including Cobalt Strike and BOF.NET.
Separate research also showed that AMSI itself can be abused for persistence by registering a malicious AMSI provider DLL as a COM server under HKLM, allowing code to run whenever AMSI-inspected content matches a trigger while still returning AMSI_RESULT_NOT_DETECTED. In the demonstrated sample, the provider watched for a specific string and launched calc.exe, highlighting how AMSI can be turned from a scanning interface into an execution mechanism. Defenders were advised to monitor unsigned DLL loads by PowerShell and registry changes affecting AMSI provider and InprocServer32 entries, as these tradecraft patterns can support stealthy post-exploitation and long-term Windows persistence.

Get the actors, campaigns, and ATT&CK mapping behind it.
5 events from the most recent confirmed update back to the earliest known activity.
On July 13, 2026, Purple Team published material describing persistence via a malicious AMSI provider DLL that registers as a COM server and AMSI provider, and can launch calc.exe when scanned content matches a trigger string.
A GitHub repository named Amsi-Bypass-Powershell was published, collecting numerous PowerShell-focused AMSI bypass and evasion methods from prior research and offensive tradecraft. The repository includes techniques such as AmsiScanBuffer patching, AmsiUtils manipulation, provider interception, DLL hijacking, PowerShell v2 fallback, and logging tampering guidance.
On June 17, 2022, Mariusz Banach (mgeeky) published the Stracciatella project, a C# tool for launching PowerShell runspaces while attempting to disable AMSI, ETW, and Script Block Logging before execution.
On June 18, 2018, MDSec published research detailing multiple PowerShell defense-evasion techniques, including AMSI bypasses via reflection and amsi.dll patching, plus script block logging bypasses through cached policy and signature manipulation.
Adam Chester's MDSec article states that Matt Graeber made an early public reference in 2016 to the AMSI bypass that uses reflection to set System.Management.Automation.AmsiUtils.amsiInitFailed to true.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
4 references tracked. Mallory keeps watching after this page renders.
ipurple.team
Open sourcegithub.com
Open sourcegithub.com
Open sourcemdsec.co.uk
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.