Back to Search Start Over

ScriptBlock Smuggling: Uncovering Stealthy Evasion Techniques in PowerShell and .NET Environments

Authors :
Anthony J. Rose
Scott R. Graham
Christine M. Schubert Kabban
Jacob J. Krasnov
Wayne C. Henry
Source :
Journal of Cybersecurity and Privacy, Vol 4, Iss 2, Pp 153-166 (2024)
Publication Year :
2024
Publisher :
MDPI AG, 2024.

Abstract

The Antimalware Scan Interface (AMSI) plays a crucial role in detecting malware within Windows operating systems. This paper presents ScriptBlock Smuggling, a novel evasion and log spoofing technique exploiting PowerShell and .NET environments to circumvent the AMSI. By focusing on the manipulation of ScriptBlocks within the Abstract Syntax Tree (AST), this method creates dual AST representations, one for compiler execution and another for antivirus and log analysis, enabling the evasion of AMSI detection and challenging traditional memory patching bypass methods. This research provides a detailed analysis of PowerShell’s ScriptBlock creation and its inherent security features and pinpoints critical limitations in the AMSI’s capabilities to scrutinize ScriptBlocks and the implications of log spoofing as part of this evasion method. The findings highlight potential avenues for attackers to exploit these vulnerabilities, suggesting the possibility of a new class of AMSI bypasses and their use for log spoofing. In response, this paper proposes a synchronization strategy for ASTs, intended to unify the compilation and malware scanning processes to reduce the threat surfaces in PowerShell and .NET environments.

Details

Language :
English
ISSN :
2624800X
Volume :
4
Issue :
2
Database :
Directory of Open Access Journals
Journal :
Journal of Cybersecurity and Privacy
Publication Type :
Academic Journal
Accession number :
edsdoj.075b576513fb46e2a215a7637d67197f
Document Type :
article
Full Text :
https://doi.org/10.3390/jcp4020008