The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Verifying AMSI detection

Prev Next

To verify AMSI module detection, execute the following sample script using PowerShell.

iex([System.Text.Encoding]::UTF8.GetString([Convert]::FromBase64String('JHJlc3AgPSBJbnZva2UtV2ViUmVxdWVzdCAtVXJpICdodHRwczovL3NlY3VyZS5laWNhci5vcmcvZWljYXIuY29tJw0KJGVpY2FyID0gW0NvbnZlcnRdOjpUb0Jhc2U2NFN0cmluZyhbU3lzdGVtLlRleHQuRW5jb2RpbmddOjpVVEY4LkdldEJ5dGVzKCRyZXNwKSkNCklFWCAnV3JpdGUtSG9zdChbU3lzdGVtLlRleHQuRW5jb2RpbmddOjpVVEY4LkdldFN0cmluZyhbQ29udmVydF06OkZyb21CYXNlNjRTdHJpbmcoJGVpY2FyKSkpJw==')))

If the AMSI module is enabled and the content is updated, you will receive the following AMSI alert Suspicious Base64 Decoding using PowerShell.