title: Windows Defender AMSI Trigger Detected author: Bhabesh Raj date: 2020/09/14 description: Detects triggering of AMSI by Windows Defender. detection: SELECTION_1: EventID: 1116 SELECTION_2: Source_Name: AMSI condition: (SELECTION_1 and SELECTION_2) falsepositives: - unlikely id: ea9bf0fa-edec-4fb8-8b78-b119f2528186 level: high logsource: product: windows service: windefend modified: 2021/10/13 references: - https://docs.microsoft.com/en-us/windows/win32/amsi/how-amsi-helps status: stable tags: - attack.execution - attack.t1059 ruletype: SIGMA