2025-05-13 22:32:43 +01:00
2025-05-13 22:32:43 +01:00
2020-05-27 10:23:28 +01:00
2020-05-27 10:22:25 +01:00
2025-05-13 22:31:07 +01:00
2020-05-27 10:17:20 +01:00
2025-05-13 22:18:17 +01:00

AMSITrigger v3

Hunting for Malicious Strings

Usage:

-i, -inputfile=VALUE       Powershell filename
-u, -url=VALUE             URL eg. https://10.1.1.1/Invoke-NinjaCopy.ps1
-f, -format=VALUE          Output Format:
                              1 - Only show Triggers
                              2 - Show Triggers with Line numbers
                              3 - Show Triggers inline with code
                              4 - Show AMSI calls (xmas tree mode)
-d, -debug                 Show Debug Info
-p, -pause=VALUE           Pause after displaying VALUE triggers  
-m, -maxsiglength=VALUE    Maximum signature Length to cater for,
                              default=2048
-c, -chunksize=VALUE       Chunk size to send to AMSIScanBuffer,
                              default=4096
-h, -?, -help              Show Help

For details see https://www.rythmstick.net/posts/amsitrigger

S
Description
Automated archival mirror of github.com/RythmStick/AMSITrigger
Readme GPL-3.0
124 KiB
Languages
C# 100%