You can enable integration with Antimalware Scan Interface (AMSI) to provide protection against non-browser-based scripts, such as PowerShell, JavaScript, and VBScript. With this feature enabled, AMSI blocks the script before execution.
AMSI is a generic interface standard provided by Microsoft and supported on Windows 10, Windows Server 2016, and Windows 2019 systems. It allows applications and services to integrate with Threat Prevention, providing better protection against malware.
Tip
Best practice: For the best protection against script-based threats, enable this option with ScriptScan, which scans browser-based scripts, and Adaptive Threat Protection enhanced scanning.
Actions and Exclusions
AMSI scanning uses the Actions and Exclusions specified for Standard process types in the Process Settings section of the On-Access Scan settings.
AMSI uses the threat detection responses specified in the Actions settings. For example, if Threat detection first response is set to Clean files, AMSI also takes this action.
AMSI excludes most files that are excluded from on-access scans. Some scripts, such as PowerShell, are fileless and are not excluded from AMSI.
Identify the module causing AMSI detections
AMSI detection events now include Detection Context and Detected Module details. This information helps you identify the specific third-party module (DLL) or script responsible for the alert. If a legitimate third-party application triggers a false positive, you can use the provided module hash to create a precise suppression rule, eliminating the need to wait for a content update.