Netskope Threat Labs

AMSI.Disable

ATP Sandbox Adv. HeuristicsAV

This detection identifies attempts to disable the Windows Antimalware Scan Interface, the mechanism that lets security products inspect script content before execution. Disabling or patching AMSI signals that a cyberattacker has code execution on the system and is preparing to deploy additional tooling.

First seen
May 2022
Last seen
October 2026
Alert Name
DeepScan:Generic.AMSI.DisableA.FFFFFFFE
Dropped:Generic.AMSI.Disable.A.461A943E
Dropped:Generic.AMSI.Disable.A.9AF64BAC
Dropped:Trojan.AMSI.Disable.A
Dropped:Trojan.AMSI.Disable.AA
Dropped:Trojan.AMSI.Disable.C
Dropped:Trojan.AMSI.Disable.I
Dump:Generic.AMSI.Disable.A.FFFFFFFE
Dump:Generic.AMSI.Disable.A.FFFFFFFE:05584
Dump:Generic.AMSI.Disable.A.FFFFFFFE:40B46