Further reading
These aids for further study will let you dive deeper into the attacks covered in the chapter:
- Great blog post with ready-to-use code for AmsiScanBufferBypass: https://fatrodzianko.com/2020/08/25/getting-rastamouses-amsiscanbufferbypass-to-work-again/.
- Excellent blog post about PowerShell CLM and examples of rule evaluation: https://p0w3rsh3ll.wordpress.com/2019/03/07/applocker-and-powershell-how-do-they-tightly-work-together/
- There is an excellent post that combines the MSBuild and InstallUtils AppLocker bypass methods: https://www.blackhillsinfosec.com/powershell-without-powershell-how-to-bypass-application-whitelisting-environment-restrictions-av/