cobbr / cobbr/PSAmsi

Defender prevents PSAmsi from working, so no malicious files can be scanned without powershell error message

Open
#8 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
PowerShell
Stars
397
Forks
71
PR merge metrics
No merged PRs in 30d

Description

Hello all,

I don't know if I understood the wiki correctly and am just missing an embarrassing error,

in any case I wanted to create true / false values, but when I try to scan a malicious file with PSamsi, only the red error message comes up in powershell that the file was blocked by my antivirus, but also PSAmsi's execution is terminated...
So I can't get a true value for the scan anymore.
If I disable defender I get false and a warning for each malicious file, but that is logical in this case.

Does anyone know what I am doing wrong?

With kind regards
Luke

Contributor guide

No contributing guide indexed for this repository

Research direction

Start by reviewing the PSAmsi wiki and reproducing the scan in PowerShell with Defender enabled, as described in the issue. Clarify whether the expected result is a true value, a false value with a warning, or different handling of Defender-blocked files before defining what done means.

Written by the indexing model from the issue text.

Assessment

Tech stack
powershell
Domain
security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.