Skip to content

Instantly share code, notes, and snippets.

@edygert
Created August 8, 2022 15:54
Show Gist options
  • Save edygert/3365c7526ddd9153fa3c2820c2832d1e to your computer and use it in GitHub Desktop.
Save edygert/3365c7526ddd9153fa3c2820c2832d1e to your computer and use it in GitHub Desktop.
AMSI commands
logman start AMSITrace -p Microsoft-Antimalware-Scan-Interface Event1 -o AMSITrace.etl -ets
cscript loveyou.js
logman stop AMSITrace -ets
AMSIScriptContentRetrieval > loveyou.log
Event1 was found using the following:
logman query providers Microsoft-Antimalware-Scan-Interface
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment