Skip to content

Instantly share code, notes, and snippets.

@r00t-3xp10it
Last active May 22, 2019 01:56
Show Gist options
  • Save r00t-3xp10it/1de77741a920fc768747728c903359eb to your computer and use it in GitHub Desktop.
Save r00t-3xp10it/1de77741a920fc768747728c903359eb to your computer and use it in GitHub Desktop.
Get amsi scriptblock signatures list
## command: [ScriptBlock].GetField('signatures','NonPublic,Static').GetValue($null)
Add-Type
DllImport
DefineDynamicAssembly
DefineDynamicModule
DefineType
DefineConstructor
CreateType
DefineLiteral
DefineEnum
DefineField
ILGenerator
Emit
UnverifiableCodeAttribute
DefinePInvokeMethod
GetTypes
GetAssemblies
Methods
Properties
GetConstructor
GetConstructors
GetDefaultMembers
GetEvent
GetEvents
GetField
GetFields
GetInterface
GetInterfaceMap
GetInterfaces
GetMember
GetMembers
GetMethod
GetMethods
GetNestedType
GetNestedTypes
GetProperties
GetProperty
InvokeMember
MakeArrayType
MakeByRefType
MakeGenericType
MakePointerType
DeclaringMethod
DeclaringType
ReflectedType
TypeHandle
TypeInitializer
UnderlyingSystemType
InteropServices
Marshal
AllocHGlobal
PtrToStructure
StructureToPtr
FreeHGlobal
IntPtr
MemoryStream
DeflateStream
FromBase64String
EncodedCommand
Bypass
ToBase64String
ExpandString
GetPowerShell
OpenProcess
VirtualAlloc
VirtualFree
WriteProcessMemory
CreateUserThread
CloseHandle
GetDelegateForFunctionPointer
kernel32
CreateThread
memcpy
LoadLibrary
GetModuleHandle
GetProcAddress
VirtualProtect
FreeLibrary
ReadProcessMemory
CreateRemoteThread
AdjustTokenPrivileges
WriteByte
WriteInt32
OpenThreadToken
PtrToString
ZeroFreeGlobalAllocUnicode
OpenProcessToken
GetTokenInformation
SetThreadToken
ImpersonateLoggedOnUser
RevertToSelf
GetLogonSessionData
CreateProcessWithToken
DuplicateTokenEx
OpenWindowStation
OpenDesktop
MiniDumpWriteDump
AddSecurityPackage
EnumerateSecurityPackages
GetProcessHandle
DangerousGetHandle
CryptoServiceProvider
Cryptography
RijndaelManaged
SHA1Managed
CryptoStream
CreateEncryptor
CreateDecryptor
TransformFinalBlock
DeviceIoControl
SetInformationProcess
PasswordDeriveBytes
GetAsyncKeyState
GetKeyboardState
GetForegroundWindow
BindingFlags
NonPublic
ScriptBlockLogging
LogPipelineExecutionDetails
ProtectedEventLogging
@r00t-3xp10it
Copy link
Author

r00t-3xp10it commented Jan 31, 2019

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment