AMSI Bypass Pattern Assembly GetType

 Original Source: [Sigma source]
Title: AMSI Bypass Pattern Assembly GetType
Status: test
Description:Detects code fragments found in small and obfuscated AMSI bypass PowerShell scripts
References:
  -https://www.mdsec.co.uk/2018/06/exploring-powershell-amsi-and-logging-evasion/
  -https://twitter.com/cyb3rops/status/1588574518057979905?s=20&t=A7hh93ONM7ni1Rj1jO5OaA
Author: Florian Roth (Nextron Systems)
Date: 2022-11-09
modified:None
Tags:
  • -'attack.defense-impairment'
  • -'attack.t1685'
  • -'attack.execution'
Logsource:
  • product: windows
  • category: ps_script
  • definition: Requirements: Script Block Logging must be enabled
Detection:
  selection:
    ScriptBlockText|contains|all:
      -'[Ref].Assembly.GetType'
      -'SetValue($null,$true)'
      -'NonPublic,Static'

  condition:selection
Falsepositives:
  -Unknown
Level: high