FreshRSS

πŸ”’
❌ Secure Planet Training Courses Updated For 2019 - Click Here
There are new available articles, click to refresh the page.
Before yesterdaySecurity

Ghosting AMSI: Cutting RPC to disarm AV

πŸ›‘ AMSI Bypass via RPC Hijack (NdrClientCall3) This technique exploits the COM-level mechanics AMSI uses when delegating scan requests to antivirus (AV) providers through RPC. By hooking into the NdrClientCall3 functionβ€”used internally by the RPC runtime to marshal and dispatch function callsβ€”we intercept AMSI scan requests before they're serialized and sent to the AV engine.

submitted by /u/Echoes-of-Tomorroww
[link] [comments]
❌