<!DOCTYPE html>
<html class="client-nojs vector-feature-language-in-header-enabled vector-feature-language-in-main-page-header-disabled vector-feature-page-tools-pinned-disabled vector-feature-toc-pinned-clientpref-0 vector-toc-not-available vector-feature-main-menu-pinned-disabled vector-feature-limited-width-clientpref-1 vector-feature-limited-width-content-enabled vector-feature-custom-font-size-clientpref-1 vector-feature-appearance-pinned-clientpref-0 skin-theme-clientpref-day vector-sticky-header-enabled" lang="de" dir="ltr"><head>
<meta charset="UTF-8">
<title>Antimalware Scan Interface</title>
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<link rel="icon" type="image/png" href="./_res_/favicon.png">
<link rel="canonical" href="https://de.wikipedia.org/wiki/Antimalware_Scan_Interface"> <link href="./_mw_/ext.cite.styles.css" rel="stylesheet" type="text/css">
<link href="./_mw_/ext.wikimediamessages.styles.css" rel="stylesheet" type="text/css">
<link href="./_mw_/skins.vector.icons.css" rel="stylesheet" type="text/css">
<link href="./_mw_/skins.vector.search.codex.styles.css" rel="stylesheet" type="text/css">
<link href="./_mw_/skins.vector.styles.css" rel="stylesheet" type="text/css">
<meta name="ResourceLoaderDynamicStyles" content="">
<link href="./_mw_/ext.gadget.citeRef.css" rel="stylesheet" type="text/css">
<link href="./_mw_/ext.gadget.defaultPlainlinks.css" rel="stylesheet" type="text/css">
<link href="./_mw_/ext.gadget.dewikiCommonHide.css" rel="stylesheet" type="text/css">
<link href="./_mw_/ext.gadget.dewikiCommonLayout.css" rel="stylesheet" type="text/css">
<link href="./_mw_/ext.gadget.dewikiCommonStyle.css" rel="stylesheet" type="text/css">
<link href="./_mw_/ext.gadget.dewikiDarkmode.css" rel="stylesheet" type="text/css">
<link href="./_mw_/ext.gadget.dewikiResponsive.css" rel="stylesheet" type="text/css">
<link href="./_mw_/ext.gadget.specialSearch.css" rel="stylesheet" type="text/css">
<link rel="stylesheet" type="text/css" href="./_mw_/site.styles.css">
<link rel="stylesheet" type="text/css" href="./_mw_/noscript.css">
<link rel="stylesheet" type="text/css" href="./_res_/footer.css">
<link rel="stylesheet" type="text/css" href="./_res_/vector-2022.css">
</head>
<body class="skin--responsive skin-vector skin-vector-search-vue mediawiki ltr sitedir-ltr mw-hide-empty-elt ns-0 ns-subject page-Antimalware_Scan_Interface rootpage-Antimalware_Scan_Interface skin-vector-2022 action-view">
<div class="mw-page-container">
<div class="mw-page-container-inner">
<div class="mw-content-container">
<main id="content" class="mw-body">
<header class="mw-body-header vector-page-titlebar">
<h1 id="firstHeading" class="firstHeading mw-first-heading"><span class="mw-page-title-main">Antimalware Scan Interface</span></h1>
</header>
<a id="top"></a>
<div id="bodyContent" class="vector-body ve-init-mw-desktopArticleTarget-targetContainer" aria-labelledby="firstHeading" data-mw-ve-target-container="">
<div id="contentSub">
<div id="mw-content-subtitle"></div>
</div>
<div id="mw-content-text" class="mw-body-content mw-content-ltr" lang="de" dir="ltr"><div class="mw-content-ltr mw-parser-output" lang="de" dir="ltr"><p>Das <b>Antimalware Scan Interface</b> (<b>AMSI</b>) ist eine von <a href="Microsoft" title="Microsoft">Microsoft</a> entwickelte <a href="Programmierschnittstelle" title="Programmierschnittstelle">Programmierschnittstelle</a>, die dazu dient, <a href="Schadprogramm" title="Schadprogramm">Schadprogramme</a> (<span style="font-style:normal;font-weight:normal"><a href="Englische_Sprache" title="Englische Sprache">englisch</a></span> <span lang="en-Latn" style="font-style:italic">Malware</span>) effektiver zu erkennen und zu bekämpfen.<sup id="cite_ref-MS_AMSI_Portal_1-0" class="reference"><a href="#cite_note-MS_AMSI_Portal-1"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-2" class="reference"><a href="#cite_note-2"><span class="cite-bracket">[</span>2<span class="cite-bracket">]</span></a></sup> Sie ermöglicht die Zusammenarbeit zwischen <a href="Anwendungssoftware" title="Anwendungssoftware">Anwendungen</a> und <a href="Antivirenprogramm" title="Antivirenprogramm">Antivirenprogrammen</a>, indem sie Antimalware-Scans innerhalb des <a href="Programmablauf" class="mw-redirect" title="Programmablauf">Programmablaufs</a> ermöglicht. Via AMSI können Programme dynamisch generierte Codefragmente oder aus anderen Quellen (z. B. aus dem Internet) bezogene <a href="Plug-in" title="Plug-in">Plugins</a> von <a href="Drittanbieter" title="Drittanbieter">Drittanbietern</a>, die zur <a href="Laufzeit_(Informatik)" title="Laufzeit (Informatik)">Laufzeit</a> ausgeführt werden sollen, auf schädliches Verhalten untersucht werden.<sup id="cite_ref-CT_Win10_Sicherheit_3-0" class="reference"><a href="#cite_note-CT_Win10_Sicherheit-3"><span class="cite-bracket">[</span>3<span class="cite-bracket">]</span></a></sup> Die Einführung von AMSI stellt einen wichtigen Schritt im Bereich der <a href="Informationssicherheit" title="Informationssicherheit">Informationssicherheit</a> dar, um die Fähigkeiten zur Erkennung und Abwehr von Bedrohungen zu verbessern.
</p>
<div class="mw-heading mw-heading2"><h2 id="Funktionsweise">Funktionsweise</h2></div>
<p>AMSI ist eine Schnittstelle, die seit <a href="Microsoft_Windows_10" title="Microsoft Windows 10">Windows 10</a> in den <a href="Betriebssystem" title="Betriebssystem">Betriebssystemen</a> von Microsoft implementiert ist, um eine tiefere und effektivere Integration von Antimalware-Programmen in Softwareanwendungen zu ermöglichen. AMSI ist in der Lage, verdächtige Aktivitäten und Inhalte während der Laufzeit eines Programms in <a href="Echtzeit" title="Echtzeit">Echtzeit</a> zu erkennen und zu blockieren.
</p><p>Die Funktionsweise von AMSI basiert auf einem mehrstufigen Prozess, der eine gründliche Analyse von ausführbarem Code und <a href="Skriptsprache" title="Skriptsprache">skriptbasierten Inhalten</a> ermöglicht. Dieser Prozess kann in folgenden Schritten zusammengefasst werden:<sup id="cite_ref-MS_AMSI_Portal_1-1" class="reference"><a href="#cite_note-MS_AMSI_Portal-1"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup>
</p>
<ol><li><b>Aufruf der Schnittstelle</b>: Eine Anwendung, sei es ein Programm oder ein Skript, ruft die AMSI-Schnittstelle auf, wenn sie einen potenziell schädlichen Code ausführen möchte. Dies geschieht entweder direkt durch die Anwendung oder durch die Umleitung von entsprechenden Betriebssystem-APIs.</li>
<li><b>Inhaltliche Analyse</b>: Der übergebene Code oder Inhalt wird in kleinere Einheiten, wie z. B. <a href="Zeichenkette" title="Zeichenkette">Zeichenketten</a> oder Bytefolgen, aufgeteilt. Dies ermöglicht eine detaillierte und granulare Analyse der Inhalte.</li>
<li><b>Scanning durch Antimalware-Produkte</b>: Die auf dem System installierte Antimalware-Software wird nun aufgerufen, um die übermittelten Inhalte zu überprüfen. Diese Software nutzt ihre <a href="Virensignatur" title="Virensignatur">Signaturen</a> und <a href="Heuristik" title="Heuristik">heuristischen</a> <a href="Algorithmus" title="Algorithmus">Algorithmen</a>, um nach bekannten Schadmustern zu suchen und verdächtige Aktivitäten zu identifizieren.</li>
<li><b>Generierung von Berichten und Bewertungen</b>: Basierend auf den Ergebnissen der Überprüfung generiert die Antimalware-Software Berichte über die erkannten Aktivitäten und deren potenzielle Risiken. Diese Informationen werden an die AMSI-Schnittstelle zurückgegeben.</li>
<li><b>Entscheidungsprozess</b>: Die AMSI-Schnittstelle entscheidet basierend auf den Berichten der Antimalware-Software, ob der übermittelte Code oder Inhalt als schädlich oder unbedenklich eingestuft wird. Bei Verdacht auf Schadhaftigkeit können entsprechende Aktionen ergriffen werden, wie z. B. die Blockierung der Ausführung.</li></ol>
<p>Ein Schlüsselmerkmal von AMSI ist seine Fähigkeit, nicht nur auf traditionelle <a href="Ausf%C3%BChrbare_Datei" title="Ausführbare Datei">ausführbare Dateien</a>, sondern auch auf Skripte zuzugreifen.<sup id="cite_ref-MS_AMSI_Portal_1-2" class="reference"><a href="#cite_note-MS_AMSI_Portal-1"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup> Dies ist entscheidend, da moderne Malware oft Skripte verwendet, um sich auf einem System auszubreiten oder ihre schädlichen Aktivitäten zu tarnen. Insbesondere gilt das auch für dateilose Bedrohungen, also Schadcode, der zur Laufzeit dynamisch generiert wird und nur im <a href="Arbeitsspeicher" title="Arbeitsspeicher">Arbeitsspeicher</a> existiert.<sup id="cite_ref-MS_AMSI_Prinzip_4-0" class="reference"><a href="#cite_note-MS_AMSI_Prinzip-4"><span class="cite-bracket">[</span>4<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-5" class="reference"><a href="#cite_note-5"><span class="cite-bracket">[</span>5<span class="cite-bracket">]</span></a></sup> Durch die Einbindung von AMSI in <a href="Laufzeitumgebung" title="Laufzeitumgebung">Laufzeitumgebungen</a> für Skriptsprachen wie <a href="PowerShell" title="PowerShell">PowerShell</a>, <a href="Windows_Script_Host" title="Windows Script Host">Windows Script Host</a> (u. a. <a href="Visual_Basic_Script" title="Visual Basic Script">VBScript</a> und <a href="JScript" title="JScript">JScript</a>) und <a href="Visual_Basic_for_Applications" title="Visual Basic for Applications">VBA</a>-<a href="Makro" title="Makro">Makros</a> in <a href="Microsoft_Office" title="Microsoft Office">Microsoft Office</a> wird die Wirksamkeit von Antimalware-Programmen erheblich verbessert.<sup id="cite_ref-MS_AMSI_Portal_1-3" class="reference"><a href="#cite_note-MS_AMSI_Portal-1"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-6" class="reference"><a href="#cite_note-6"><span class="cite-bracket">[</span>6<span class="cite-bracket">]</span></a></sup> Durch einfache <a href="Obfuskation_(Software)" title="Obfuskation (Software)">Code-Obfuskation</a> lässt sich eine AMSI-Überprüfung nicht umgehen oder beeinflussen, da die Prüfung unmittelbar vor der Ausführung durch die Laufzeitumgebung stattfindet und zu diesem Zeitpunkt unverschleiert vorliegen muss.<sup id="cite_ref-MS_AMSI_Prinzip_4-1" class="reference"><a href="#cite_note-MS_AMSI_Prinzip-4"><span class="cite-bracket">[</span>4<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-7" class="reference"><a href="#cite_note-7"><span class="cite-bracket">[</span>7<span class="cite-bracket">]</span></a></sup>
</p><p>Standardmäßig werden die Anfragen an die AMSI-Schnittstelle durch den <a href="Microsoft_Defender" title="Microsoft Defender">Microsoft Defender</a> bearbeitet. Allerdings können auch andere Antivirenprogramme hierfür registriert werden, sofern dies durch den Hersteller und die Benutzereinstellungen unterstützt wird.<sup id="cite_ref-CT_Win10_Sicherheit_3-1" class="reference"><a href="#cite_note-CT_Win10_Sicherheit-3"><span class="cite-bracket">[</span>3<span class="cite-bracket">]</span></a></sup> Es können mehrere AMSI-Anbieter registriert werden, die nacheinander durchlaufen werden.<sup id="cite_ref-8" class="reference"><a href="#cite_note-8"><span class="cite-bracket">[</span>8<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading2"><h2 id="Kritik">Kritik</h2></div>
<p>Trotz seiner potenziellen Vorteile und der Fortschritte im Bereich der Malware-Erkennung hat das Antimalware Scan Interface (AMSI) auch Kritik und Bedenken hervorgerufen. Einige Sicherheitsexperten argumentieren, dass AMSI nicht immun gegen Umgehungsversuche und <a href="Fehlklassifikation" class="mw-redirect" title="Fehlklassifikation">Fehlklassifikation</a> ist.<sup id="cite_ref-9" class="reference"><a href="#cite_note-9"><span class="cite-bracket">[</span>9<span class="cite-bracket">]</span></a></sup> Angreifer könnten versuchen, die AMSI-Überprüfung zu umgehen, indem sie Techniken anwenden, die schädlichen Code vor der Erkennung verbergen oder den AMSI-Prozess selbst manipulieren.<sup id="cite_ref-10" class="reference"><a href="#cite_note-10"><span class="cite-bracket">[</span>10<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-11" class="reference"><a href="#cite_note-11"><span class="cite-bracket">[</span>11<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-12" class="reference"><a href="#cite_note-12"><span class="cite-bracket">[</span>12<span class="cite-bracket">]</span></a></sup> Zudem können Fehlalarme auftreten, bei denen legitimer Code fälschlicherweise als schädlich eingestuft wird, was zu Unterbrechungen in rechtmäßigen Aktivitäten führen kann. Obwohl AMSI zweifellos eine wichtige Rolle im Schutz vor Malware spielt, sind solche Bedenken wichtige Aspekte, die bei der Entwicklung und <a href="Implementierung" title="Implementierung">Implementierung</a> dieser Technologie berücksichtigt werden müssen.
</p>
<div class="mw-heading mw-heading2"><h2 id="Einzelnachweise">Einzelnachweise</h2></div>
<ol class="references">
<li id="cite_note-MS_AMSI_Portal-1"><span class="mw-cite-backlink">↑ <sup><a href="#cite_ref-MS_AMSI_Portal_1-0">a</a></sup> <sup><a href="#cite_ref-MS_AMSI_Portal_1-1">b</a></sup> <sup><a href="#cite_ref-MS_AMSI_Portal_1-2">c</a></sup> <sup><a href="#cite_ref-MS_AMSI_Portal_1-3">d</a></sup></span> <span class="reference-text"><span class="cite">Alvin Ashcraft et al.: <a rel="nofollow" class="external text" href="https://learn.microsoft.com/de-de/windows/win32/amsi/antimalware-scan-interface-portal"><i>Antimalware Scan Interface (AMSI).</i></a> In: <i>learn.microsoft.com.</i> Microsoft, 4. Juli 2023,<span class="Abrufdatum"> abgerufen am 3. August 2023</span>.</span><span style="display: none;" class="Z3988" title="ctx_ver=Z39.88-2004&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Adc&rfr_id=info%3Asid%2Fde.wikipedia.org%3AAntimalware+Scan+Interface&rft.title=Antimalware+Scan+Interface+%28AMSI%29&rft.description=Antimalware+Scan+Interface+%28AMSI%29&rft.identifier=https%3A%2F%2Flearn.microsoft.com%2Fde-de%2Fwindows%2Fwin32%2Famsi%2Fantimalware-scan-interface-portal&rft.creator=Alvin+Ashcraft+et+al.&rft.publisher=Microsoft&rft.date=2023-07-04&rft.language=de"> </span></span>
</li>
<li id="cite_note-2"><span class="mw-cite-backlink"><a href="#cite_ref-2">↑</a></span> <span class="reference-text"><span class="cite"><a rel="nofollow" class="external text" href="https://support.kaspersky.com/KAV/21.2/de-DE/185854.htm"><i>Über den Schutz mithilfe von Antimalware Scan Interface.</i></a> In: <i>support.kaspersky.com.</i> AO Kaspersky Lab, 31. August 2020,<span class="Abrufdatum"> abgerufen am 3. August 2023</span> (englisch).</span><span style="display: none;" class="Z3988" title="ctx_ver=Z39.88-2004&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Adc&rfr_id=info%3Asid%2Fde.wikipedia.org%3AAntimalware+Scan+Interface&rft.title=%C3%9Cber+den+Schutz+mithilfe+von+Antimalware+Scan+Interface&rft.description=%C3%9Cber+den+Schutz+mithilfe+von+Antimalware+Scan+Interface&rft.identifier=https%3A%2F%2Fsupport.kaspersky.com%2FKAV%2F21.2%2Fde-DE%2F185854.htm&rft.publisher=AO+Kaspersky+Lab&rft.date=2020-08-31&rft.language=en"> </span></span>
</li>
<li id="cite_note-CT_Win10_Sicherheit-3"><span class="mw-cite-backlink">↑ <sup><a href="#cite_ref-CT_Win10_Sicherheit_3-0">a</a></sup> <sup><a href="#cite_ref-CT_Win10_Sicherheit_3-1">b</a></sup></span> <span class="reference-text">Jo Bager et al.: <cite style="font-style:italic">Die Neuerungen</cite>. In: <cite style="font-style:italic"><a href="C%E2%80%99t" title="C’t">c’t</a>: Windows 10 – Das Kompendium</cite>. Heise Medien, 2016, ISBN 978-3-95788-078-9, Sicherheit, <span style="white-space:nowrap">S.<span style="display:inline-block;width:.2em"> </span>15<span style="display:inline-block;width:.2em"> </span>f</span>. (<a rel="nofollow" class="external text" href="https://books.google.de/books?id=69yNDAAAQBAJ&pg=PA15#v=onepage">eingeschränkte Vorschau</a> in der Google-Buchsuche).<span class="Z3988" title="ctx_ver=Z39.88-2004&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Abook&rfr_id=info:sid/de.wikipedia.org:Antimalware+Scan+Interface&rft.atitle=Die+Neuerungen&rft.au=Jo+Bager+et+al.&rft.btitle=c%E2%80%99t%3A+Windows+10+-+Das+Kompendium&rft.date=2016&rft.genre=book&rft.isbn=9783957880789&rft.pages=15f&rft.pub=Heise+Medien" style="display:none"> </span></span>
</li>
<li id="cite_note-MS_AMSI_Prinzip-4"><span class="mw-cite-backlink">↑ <sup><a href="#cite_ref-MS_AMSI_Prinzip_4-0">a</a></sup> <sup><a href="#cite_ref-MS_AMSI_Prinzip_4-1">b</a></sup></span> <span class="reference-text"><span class="cite">Alvin Ashcraft: <a rel="nofollow" class="external text" href="https://learn.microsoft.com/de-de/windows/win32/amsi/how-amsi-helps"><i>Wie das Antimalware Scan Interface (AMSI) Ihnen hilft, sich gegen Schadsoftware zu schützen.</i></a> In: <i>learn.microsoft.com.</i> Microsoft, 4. Juli 2023,<span class="Abrufdatum"> abgerufen am 15. August 2023</span>.</span><span style="display: none;" class="Z3988" title="ctx_ver=Z39.88-2004&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Adc&rfr_id=info%3Asid%2Fde.wikipedia.org%3AAntimalware+Scan+Interface&rft.title=Wie+das+Antimalware+Scan+Interface+%28AMSI%29+Ihnen+hilft%2C+sich+gegen+Schadsoftware+zu+sch%C3%BCtzen&rft.description=Wie+das+Antimalware+Scan+Interface+%28AMSI%29+Ihnen+hilft%2C+sich+gegen+Schadsoftware+zu+sch%C3%BCtzen&rft.identifier=https%3A%2F%2Flearn.microsoft.com%2Fde-de%2Fwindows%2Fwin32%2Famsi%2Fhow-amsi-helps&rft.creator=Alvin+Ashcraft&rft.publisher=Microsoft&rft.date=2023-07-04&rft.language=de"> </span></span>
</li>
<li id="cite_note-5"><span class="mw-cite-backlink"><a href="#cite_ref-5">↑</a></span> <span class="reference-text"><span class="cite">Daniel Simpson et al.: <a rel="nofollow" class="external text" href="https://web.archive.org/web/20230817085712/https://learn.microsoft.com/de-de/microsoft-365/security/intelligence/fileless-threats?view=o365-worldwide"><i>Dateilose Bedrohungen.</i></a> In: <i>learn.microsoft.com.</i> Microsoft, 23. August 2019, archiviert vom <style data-mw-deduplicate="TemplateStyles:r250917974">
/* start https://de.wikipedia.org/ */
.mw-parser-output .dewiki-iconexternal>a{background-position:center right!important;background-repeat:no-repeat!important}body.skin-minerva .mw-parser-output .dewiki-iconexternal>a{background-image:url("./_mw_/OOjs_UI_icon_external-link-ltr-progressive.svg")!important;background-size:10px!important;padding-right:13px!important}body.skin-timeless .mw-parser-output .dewiki-iconexternal>a,body.skin-monobook .mw-parser-output .dewiki-iconexternal>a{background-image:url("./_mw_/MediaWiki_external_link_icon.svg")!important;padding-right:13px!important}body.skin-vector .mw-parser-output .dewiki-iconexternal>a{background-image:url("./_mw_/Link.ernal-small-ltr-progressive.svg")!important;background-size:0.857em!important;padding-right:1em!important}
/* end https://de.wikipedia.org/ */
</style><span class="dewiki-iconexternal"><a class="external text" href="https://redirecter.toolforge.org/?url=https%3A%2F%2Flearn.microsoft.com%2Fde-de%2Fmicrosoft-365%2Fsecurity%2Fintelligence%2Ffileless-threats">Original</a></span> am <span style="white-space:nowrap;">17. August 2023</span><span>;</span><span class="Abrufdatum"> abgerufen am 15. August 2023</span>.</span><span style="display: none;" class="Z3988" title="ctx_ver=Z39.88-2004&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Adc&rfr_id=info%3Asid%2Fde.wikipedia.org%3AAntimalware+Scan+Interface&rft.title=Dateilose+Bedrohungen&rft.description=Dateilose+Bedrohungen&rft.identifier=https%3A%2F%2Fweb.archive.org%2Fweb%2F20230817085712%2Fhttps%3A%2F%2Flearn.microsoft.com%2Fde-de%2Fmicrosoft-365%2Fsecurity%2Fintelligence%2Ffileless-threats%3Fview%3Do365-worldwide&rft.creator=Daniel+Simpson+et+al.&rft.publisher=Microsoft&rft.date=2019-08-23&rft.source=https://learn.microsoft.com/de-de/microsoft-365/security/intelligence/fileless-threats&rft.language=de"> </span></span>
</li>
<li id="cite_note-6"><span class="mw-cite-backlink"><a href="#cite_ref-6">↑</a></span> <span class="reference-text"><span class="cite"><a rel="nofollow" class="external text" href="https://www.microsoft.com/en-us/security/blog/2018/09/12/office-vba-amsi-parting-the-veil-on-malicious-macros/"><i>Office VBA + AMSI: Parting the veil on malicious macros.</i></a> In: <i>microsoft.com.</i> Microsoft, 12. September 2018,<span class="Abrufdatum"> abgerufen am 14. August 2023</span> (englisch).</span><span style="display: none;" class="Z3988" title="ctx_ver=Z39.88-2004&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Adc&rfr_id=info%3Asid%2Fde.wikipedia.org%3AAntimalware+Scan+Interface&rft.title=Office+VBA+%2B+AMSI%3A+Parting+the+veil+on+malicious+macros&rft.description=Office+VBA+%2B+AMSI%3A+Parting+the+veil+on+malicious+macros&rft.identifier=https%3A%2F%2Fwww.microsoft.com%2Fen-us%2Fsecurity%2Fblog%2F2018%2F09%2F12%2Foffice-vba-amsi-parting-the-veil-on-malicious-macros%2F&rft.publisher=Microsoft&rft.date=2018-09-12&rft.language=en"> </span></span>
</li>
<li id="cite_note-7"><span class="mw-cite-backlink"><a href="#cite_ref-7">↑</a></span> <span class="reference-text">Mathias Gut, Markus Kammermann: <cite style="font-style:italic">CompTIA Security+: IT-Sicherheit verständlich erklärt – Die umfassende Prüfungsvorbereitung zur CompTIA-Prüfung SYO-601</cite>. MITP, 2021, ISBN 978-3-7475-0256-3, <span style="white-space:nowrap">S.<span style="display:inline-block;width:.2em"> </span>341</span> (<a rel="nofollow" class="external text" href="https://books.google.de/books?id=CyM-EAAAQBAJ&pg=PA341#v=onepage">eingeschränkte Vorschau</a> in der Google-Buchsuche).<span class="Z3988" title="ctx_ver=Z39.88-2004&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Abook&rfr_id=info:sid/de.wikipedia.org:Antimalware+Scan+Interface&rft.au=Mathias+Gut%2C+Markus+Kammermann&rft.btitle=CompTIA+Security%2B%3A+IT-Sicherheit+verst%C3%A4ndlich+erkl%C3%A4rt+-+Die+umfassende+Pr%C3%BCfungsvorbereitung+zur+CompTIA-Pr%C3%BCfung+SYO-601&rft.date=2021&rft.genre=book&rft.isbn=9783747502563&rft.pages=341&rft.pub=MITP" style="display:none"> </span></span>
</li>
<li id="cite_note-8"><span class="mw-cite-backlink"><a href="#cite_ref-8">↑</a></span> <span class="reference-text"><span class="cite">Tal Liberman: <a rel="nofollow" class="external text" href="https://i.blackhat.com/briefings/asia/2018/asia-18-Tal-Liberman-Documenting-the-Undocumented-The-Rise-and-Fall-of-AMSI.pdf"><i>The Rise and Fall of AMSI.</i></a> (PDF 2,7 MB) In: <i><a href="Black_Hat_Briefings" title="Black Hat Briefings">Black Hat Briefings</a>.</i> Polarium, 2018, <span style="white-space:nowrap;">S. 46–49</span>,<span class="Abrufdatum"> abgerufen am 17. August 2023</span> (englisch).</span><span style="display: none;" class="Z3988" title="ctx_ver=Z39.88-2004&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Adc&rfr_id=info%3Asid%2Fde.wikipedia.org%3AAntimalware+Scan+Interface&rft.title=The+Rise+and+Fall+of+AMSI&rft.description=The+Rise+and+Fall+of+AMSI&rft.identifier=https%3A%2F%2Fi.blackhat.com%2Fbriefings%2Fasia%2F2018%2Fasia-18-Tal-Liberman-Documenting-the-Undocumented-The-Rise-and-Fall-of-AMSI.pdf&rft.creator=Tal+Liberman&rft.publisher=Polarium&rft.date=2018&rft.language=en"> </span></span>
</li>
<li id="cite_note-9"><span class="mw-cite-backlink"><a href="#cite_ref-9">↑</a></span> <span class="reference-text"><span class="cite">Charlie Osborne: <a rel="nofollow" class="external text" href="https://www.zdnet.com/article/this-is-how-attackers-bypass-microsoft-antimalware-scan-software-amsi/"><i>This is how attackers bypass Microsoft’s AMSI anti-malware scanning protection.</i></a> In: <i>zdnet.com.</i> <a href="Ziff_Davis" title="Ziff Davis">ZDNet</a>, 2. Juni 2021,<span class="Abrufdatum"> abgerufen am 3. August 2023</span> (englisch).</span><span style="display: none;" class="Z3988" title="ctx_ver=Z39.88-2004&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Adc&rfr_id=info%3Asid%2Fde.wikipedia.org%3AAntimalware+Scan+Interface&rft.title=This+is+how+attackers+bypass+Microsoft%E2%80%99s+AMSI+anti-malware+scanning+protection&rft.description=This+is+how+attackers+bypass+Microsoft%E2%80%99s+AMSI+anti-malware+scanning+protection&rft.identifier=https%3A%2F%2Fwww.zdnet.com%2Farticle%2Fthis-is-how-attackers-bypass-microsoft-antimalware-scan-software-amsi%2F&rft.creator=Charlie+Osborne&rft.publisher=%5B%5BZiff+Davis%7CZDNet%5D%5D&rft.date=2021-06-02&rft.language=en"> </span></span>
</li>
<li id="cite_note-10"><span class="mw-cite-backlink"><a href="#cite_ref-10">↑</a></span> <span class="reference-text"><span class="cite">Panos Gkatziroulis: <a rel="nofollow" class="external text" href="https://pentestlaboratories.com/2021/05/17/amsi-bypass-methods/"><i>AMSI Bypass Methods.</i></a> In: <i>pentestlaboratories.com.</i> Pentest Laboratories, 17. Mai 2021,<span class="Abrufdatum"> abgerufen am 13. August 2023</span> (englisch).</span><span style="display: none;" class="Z3988" title="ctx_ver=Z39.88-2004&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Adc&rfr_id=info%3Asid%2Fde.wikipedia.org%3AAntimalware+Scan+Interface&rft.title=AMSI+Bypass+Methods&rft.description=AMSI+Bypass+Methods&rft.identifier=https%3A%2F%2Fpentestlaboratories.com%2F2021%2F05%2F17%2Famsi-bypass-methods%2F&rft.creator=Panos+Gkatziroulis&rft.publisher=Pentest+Laboratories&rft.date=2021-05-17&rft.language=en"> </span></span>
</li>
<li id="cite_note-11"><span class="mw-cite-backlink"><a href="#cite_ref-11">↑</a></span> <span class="reference-text"><span class="cite">Mesut Cetin: <a rel="nofollow" class="external text" href="https://redteamer.de/index.php/2023/12/06/amsi-bypass-2023-5-techniken-fur-edr-av-systeme/"><i>AMSI Bypass 2023: 5 Techniken für EDR/AV-Systeme.</i></a> In: <i>redteamer.de.</i> RedTeamer IT Security, 14. Juli 2023,<span class="Abrufdatum"> abgerufen am 13. August 2023</span>.</span><span style="display: none;" class="Z3988" title="ctx_ver=Z39.88-2004&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Adc&rfr_id=info%3Asid%2Fde.wikipedia.org%3AAntimalware+Scan+Interface&rft.title=AMSI+Bypass+2023%3A+5+Techniken+f%C3%BCr+EDR%2FAV-Systeme&rft.description=AMSI+Bypass+2023%3A+5+Techniken+f%C3%BCr+EDR%2FAV-Systeme&rft.identifier=https%3A%2F%2Fredteamer.de%2Findex.php%2F2023%2F12%2F06%2Famsi-bypass-2023-5-techniken-fur-edr-av-systeme%2F&rft.creator=Mesut+Cetin&rft.publisher=RedTeamer+IT+Security&rft.date=2023-07-14&rft.language=de"> </span></span>
</li>
<li id="cite_note-12"><span class="mw-cite-backlink"><a href="#cite_ref-12">↑</a></span> <span class="reference-text"><span class="cite">Surya Dev Singh: <a rel="nofollow" class="external text" href="https://infosecwriteups.com/amsi-bypass-new-way-2023-d506345944e9"><i>AMSI Bypass New Way 2023.</i></a> In: <i>infosecwriteups.com.</i> 11. März 2023,<span class="Abrufdatum"> abgerufen am 13. August 2023</span> (englisch).</span><span style="display: none;" class="Z3988" title="ctx_ver=Z39.88-2004&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Adc&rfr_id=info%3Asid%2Fde.wikipedia.org%3AAntimalware+Scan+Interface&rft.title=AMSI+Bypass+New+Way+2023&rft.description=AMSI+Bypass+New+Way+2023&rft.identifier=https%3A%2F%2Finfosecwriteups.com%2Famsi-bypass-new-way-2023-d506345944e9&rft.creator=Surya+Dev+Singh&rft.date=2023-03-11&rft.language=en"> </span></span>
</li>
</ol></div><!--htdig_noindex--><div><div class="zim-footer">
Dieser Artikel wurde von <a class="external text" title="Zuletzt bearbeitet am 2025-06-06" href="https://de.wikipedia.org/wiki/?title=Antimalware_Scan_Interface&oldid=256737055">Wikipedia</a> herausgegeben. Der Text ist unter <a class="external text" href="https://creativecommons.org/licenses/by-sa/4.0/deed.de">Creative Commons Attribution-Share Alike 4.0</a> verfügbar, sofern nicht anders angegeben. Für die Mediendateien können zusätzliche Bedingungen gelten.
</div>
</div><!--/htdig_noindex--></div>
</div>
</main>
</div>
</div>
</div>
<script src="./_webp_/webpHandler.js"></script>
</body></html>