AMSI in the HEAP x32

This write up is based upon the work of Matt Graeber @Mattifestation Tools Used IDA Windbg If we load up amsi.dll in IDA or equivalent tool and start looking at AmsiScanBuffer we can see that there is a check to see if the value which is pointed to via rbx equals 49534D41h (AMSI).