Back to Search
Start Over
ScriptBlock Smuggling: Uncovering Stealthy Evasion Techniques in PowerShell and .NET Environments
- Source :
- Journal of Cybersecurity and Privacy, Vol 4, Iss 2, Pp 153-166 (2024)
- Publication Year :
- 2024
- Publisher :
- MDPI AG, 2024.
-
Abstract
- The Antimalware Scan Interface (AMSI) plays a crucial role in detecting malware within Windows operating systems. This paper presents ScriptBlock Smuggling, a novel evasion and log spoofing technique exploiting PowerShell and .NET environments to circumvent the AMSI. By focusing on the manipulation of ScriptBlocks within the Abstract Syntax Tree (AST), this method creates dual AST representations, one for compiler execution and another for antivirus and log analysis, enabling the evasion of AMSI detection and challenging traditional memory patching bypass methods. This research provides a detailed analysis of PowerShell’s ScriptBlock creation and its inherent security features and pinpoints critical limitations in the AMSI’s capabilities to scrutinize ScriptBlocks and the implications of log spoofing as part of this evasion method. The findings highlight potential avenues for attackers to exploit these vulnerabilities, suggesting the possibility of a new class of AMSI bypasses and their use for log spoofing. In response, this paper proposes a synchronization strategy for ASTs, intended to unify the compilation and malware scanning processes to reduce the threat surfaces in PowerShell and .NET environments.
Details
- Language :
- English
- ISSN :
- 2624800X
- Volume :
- 4
- Issue :
- 2
- Database :
- Directory of Open Access Journals
- Journal :
- Journal of Cybersecurity and Privacy
- Publication Type :
- Academic Journal
- Accession number :
- edsdoj.075b576513fb46e2a215a7637d67197f
- Document Type :
- article
- Full Text :
- https://doi.org/10.3390/jcp4020008