frida_win_amsi_bypass
Bypass AMSI on a target process by patching AmsiScanBuffer to return E_INVALIDARG, causing content to be treated as clean.
Instructions
[Windows] Patch AmsiScanBuffer to bypass AMSI scanning.
Overwrites amsi!AmsiScanBuffer to always return E_INVALIDARG, causing callers to treat content as clean. Standard AMSI bypass.
target: process name or pid (string).
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| target | Yes |