Obfuscating API Patches to Bypass New Windows Defender Behavior Signatures
Introduction I’ve got a short post today based on some recent changes by Windows Defender. Over the weekend, I noticed that some of my unit tests began failing on code that had not been recently changed. Upon further investigation, I found that it was specifically related to the AMSI bypass through API call patching. This […]
Obfuscating API Patches to Bypass New Windows Defender Behavior Signatures Read More »