The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Verifying AMSI detection

Prev Next

To verify AMSI module detection, execute the following sample script using PowerShell.

iex([System.Text.Encoding]::UTF8.GetString([Convert]::FromBase64String('JHJlc3AgPSBJbnZva2UtV2ViUmVxdWVzdCAtVXJpICdodHRwczovL3NlY3VyZS5laWNhci5vcmcvZWljYXIuY29tJw0KJGVpY2FyID0gW0NvbnZlcnRdOjpUb0Jhc2U2NFN0cmluZyhbU3lzdGVtLlRleHQuRW5jb2RpbmddOjpVVEY4LkdldEJ5dGVzKCRyZXNwKSkNCklFWCAnV3JpdGUtSG9zdChbU3lzdGVtLlRleHQuRW5jb2RpbmddOjpVVEY4LkdldFN0cmluZyhbQ29udmVydF06OkZyb21CYXNlNjRTdHJpbmcoJGVpY2FyKSkpJw==')))

If the AMSI module is enabled and the content is updated, you will receive the following AMSI alert Suspicious Base64 Decoding using PowerShell.