title: Amsi.DLL Load By Uncommon Process id: facd1549-e416-48e0-b8c4-41d7215eedc8 status: test description: Detects loading of Amsi.dll by uncommon processes references: - https://infosecwriteups.com/amsi-bypass-new-way-2023-d506345944e9 - https://github.com/TheD1rkMtr/AMSI_patch - https://github.com/surya-dev-singh/AmsiBypass-OpenSession author: frack113 date: 2023-03-12 modified: 2026-06-29 tags: - attack.impact - attack.t1490 - detection.threat-hunting logsource: category: image_load product: windows detection: selection: ImageLoaded|endswith: '\amsi.dll' filter_main_exact: Image|endswith: - ':\Windows\explorer.exe' - ':\Windows\Sysmon64.exe' - ':\Windows\Sysmon64a.exe' filter_main_generic: Image|contains: - ':\Program Files (x86)\' - ':\Program Files\' - ':\Windows\System32\' - ':\Windows\SysWOW64\' - ':\Windows\WinSxS\' filter_optional_defender: Image|contains: ':\ProgramData\Microsoft\Windows Defender\Platform\' Image|endswith: '\MsMpEng.exe' filter_main_dotnet: Image|contains: - ':\Windows\Microsoft.NET\Framework\' - ':\Windows\Microsoft.NET\Framework64\' - ':\Windows\Microsoft.NET\FrameworkArm\' - ':\Windows\Microsoft.NET\FrameworkArm64\' Image|endswith: '\ngentask.exe' filter_main_null: Image: null filter_main_empty: Image: '' condition: selection and not 1 of filter_main_* and not 1 of filter_optional_* falsepositives: - Legitimate third party apps installed in "ProgramData" and "AppData" might generate some false positives. Apply additional filters accordingly level: low