Skip to content

Triggering AMSI detection in Windows Defender #42284

Open
@secabstraction

Description

@secabstraction
  • VSCode Version: 1.19.3
  • OS Version: 10.0.16299.0

Steps to Reproduce:

  1. Open PowerShell project in VS Code

Does this issue occur when all extensions are disabled?: No

Disabling PowerShell extension seems to kill the AMSI detection in windows defender. Looks like it might be tied to the PowerShell Integrated Console.

Trojan:PowerShell/Peasecto.A

Affected items:
amsi:PowerShell_C:\windows\System32\WindowsPowerShell\v1.0\powershell.exe_10.0.16299.15000000000000000a
amsi:PowerShell_C:\windows\System32\WindowsPowerShell\v1.0\powershell.exe_10.0.16299.15000000000000000b

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions