Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

issue about AmsiProvider #45

Closed
Woniuke opened this issue Aug 24, 2018 · 1 comment
Closed

issue about AmsiProvider #45

Woniuke opened this issue Aug 24, 2018 · 1 comment

Comments

@Woniuke
Copy link

Woniuke commented Aug 24, 2018

Hello~!
For some purpose , I want to monitor powershell script when it's running.
According to the sourcecode from https://github.com/PowerShell/PowerShell/blob/master/src/System.Management.Automation/engine/runtime/CompiledScriptBlock.cs
I find the AMSI function will be called before compiling. So I make a test follow the instruction of AmsiProvider , But I can only see the function named CloseSession has been called , The scan function never have been called at all . The testing environment is Win10x86,16299,RS3

@oldnewthing
Copy link
Member

Does the logging work if you use the instructions in the README? If so, then this is not an issue with the sample.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants