Microsoft pushed an AMSI update on April 14. Three popular evasions stopped working overnight.
- Dead: classic
amsi.dllunhook viaVirtualProtect. - Dead: hardware-breakpoint patches in PowerShell 5.x.
- Dead:
AmsiScanBufferreturn-value tampering with the old offset. - Alive: indirect syscalls combined with a fresh offset.