Windows AMSI Related Registry Tampering Via CommandLine

Last updated on:

In this page

About the rule

Rule Type

Standard

Rule Description

Detects tampering of AMSI (Anti-Malware Scan Interface) related registry values via command line tools such as reg.exe or PowerShell.

Severity

Trouble

Detection

Execution Mode

realtime

Log Sources

Windows

Author

@Swachchhanda Shrawan Poudel (Nextron Systems)