{"adoption": {"forks": 181, "observed_at": "2026-08-28T04:04:39.806505+00:00", "stars": 1415}, "canonical_url": "https://ross.abutalabs.com/products/amsitrigger", "card": {"archived": false, "artifact_type": "cli-tool", "description": "The Hunt for Malicious Strings", "domain": ["security", "penetration-testing", "developer-tools"], "enriched": true, "function": ["security", "penetration-testing", "cli"], "health_score": 46, "homepage": null, "language": "C#", "license": "GPL-3.0", "license_family": "copyleft", "maturity": "active", "member_repos": ["RythmStick/AMSITrigger"], "name": "RythmStick/AMSITrigger", "platform": ["windows", "cross-platform", "cli"], "pushed_at": "2025-05-13T21:32:43+00:00", "repo": "RythmStick/AMSITrigger", "stars": 1415, "tags": ["amsi", "powershell", "malware-analysis", "red-team", "signature-scanning", "csharp"], "topics": [], "urls": [], "use_cases": ["find which lines of my powershell script trigger defender", "identify amsi signatures in a ps1 file", "test if a powershell payload gets flagged by amsi", "scan a script from a url for malicious string detections", "pinpoint the exact code causing av detection in my tooling"], "what_it_is": "AMSITrigger is a C# command-line tool that identifies the specific strings in PowerShell scripts that trigger Microsoft's Antimalware Scan Interface (AMSI) detections. It feeds script chunks to AmsiScanBuffer and reports which code segments would be flagged as malicious.", "when_to_avoid": ["you need general antivirus scanning or malware removal", "you are analyzing non-PowerShell payloads", "you need runtime AMSI bypass rather than static trigger identification"], "when_to_choose": ["you write or modify PowerShell offensive tooling and need to know what triggers AMSI", "you want to isolate the minimal malicious snippet in a large script", "you need a fast local signature check before running a script"]}, "data_as_of": "2026-08-30T08:39:29.467469+00:00", "members": [{"path": "/products/amsitrigger", "repo": "RythmStick/AMSITrigger", "role": "main", "score": 32}], "provenance": {"archived": {"kind": "observed", "observed_at": "2026-08-28T04:04:39.806505+00:00", "source": "github"}, "artifact_type": {"confidence": null, "enriched_at": "2026-08-30T04:38:08.075963+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "0248110a1432a6b92f14b898c2685d06911f005297c66d9322763372da503cae", "fetched_at": "2026-08-28T04:04:39.806505+00:00", "kind": "readme", "missing": false, "url": "https://github.com/RythmStick/AMSITrigger"}], "taxonomy_version": 1}, "description": {"kind": "observed", "observed_at": "2026-08-28T04:04:39.806505+00:00", "source": "github"}, "domain": {"confidence": null, "enriched_at": "2026-08-30T04:38:08.075963+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "0248110a1432a6b92f14b898c2685d06911f005297c66d9322763372da503cae", "fetched_at": "2026-08-28T04:04:39.806505+00:00", "kind": "readme", "missing": false, "url": "https://github.com/RythmStick/AMSITrigger"}], "taxonomy_version": 1}, "enriched": {"inputs": [], "kind": "computed", "method": "enrichment_status"}, "function": {"confidence": null, "enriched_at": "2026-08-30T04:38:08.075963+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "0248110a1432a6b92f14b898c2685d06911f005297c66d9322763372da503cae", "fetched_at": "2026-08-28T04:04:39.806505+00:00", "kind": "readme", "missing": false, "url": "https://github.com/RythmStick/AMSITrigger"}], "taxonomy_version": 1}, "health_score": {"inputs": ["days_since_push", "days_since_release", "archived"], "kind": "computed", "method": "health_v1"}, "homepage": {"kind": "observed", "observed_at": "2026-08-28T04:04:39.806505+00:00", "source": "github"}, "language": {"kind": "observed", "observed_at": "2026-08-28T04:04:39.806505+00:00", "source": "github"}, "license": {"kind": "observed", "observed_at": "2026-08-28T04:04:39.806505+00:00", "source": "github"}, "license_family": {"inputs": ["license"], "kind": "computed", "method": "license_family"}, "maturity": {"confidence": null, "enriched_at": "2026-08-30T04:38:08.075963+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "0248110a1432a6b92f14b898c2685d06911f005297c66d9322763372da503cae", "fetched_at": "2026-08-28T04:04:39.806505+00:00", "kind": "readme", "missing": false, "url": "https://github.com/RythmStick/AMSITrigger"}], "taxonomy_version": 1}, "member_repos": {"kind": "observed", "observed_at": "2026-08-28T04:04:39.806505+00:00", "source": "github"}, "name": {"kind": "observed", "observed_at": "2026-08-28T04:04:39.806505+00:00", "source": "github"}, "platform": {"confidence": null, "enriched_at": "2026-08-30T04:38:08.075963+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "0248110a1432a6b92f14b898c2685d06911f005297c66d9322763372da503cae", "fetched_at": "2026-08-28T04:04:39.806505+00:00", "kind": "readme", "missing": false, "url": "https://github.com/RythmStick/AMSITrigger"}], "taxonomy_version": 1}, "pushed_at": {"kind": "observed", "observed_at": "2026-08-28T04:04:39.806505+00:00", "source": "github"}, "repo": {"kind": "observed", "observed_at": "2026-08-28T04:04:39.806505+00:00", "source": "github"}, "stars": {"kind": "observed", "observed_at": "2026-08-28T04:04:39.806505+00:00", "source": "github"}, "tags": {"confidence": null, "enriched_at": "2026-08-30T04:38:08.075963+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "0248110a1432a6b92f14b898c2685d06911f005297c66d9322763372da503cae", "fetched_at": "2026-08-28T04:04:39.806505+00:00", "kind": "readme", "missing": false, "url": "https://github.com/RythmStick/AMSITrigger"}], "taxonomy_version": 1}, "topics": {"kind": "observed", "observed_at": "2026-08-28T04:04:39.806505+00:00", "source": "github"}, "urls": {"kind": "observed", "observed_at": "2026-08-28T04:04:39.806505+00:00", "source": "github"}, "use_cases": {"confidence": null, "enriched_at": "2026-08-30T04:38:08.075963+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "0248110a1432a6b92f14b898c2685d06911f005297c66d9322763372da503cae", "fetched_at": "2026-08-28T04:04:39.806505+00:00", "kind": "readme", "missing": false, "url": "https://github.com/RythmStick/AMSITrigger"}], "taxonomy_version": 1}, "what_it_is": {"confidence": null, "enriched_at": "2026-08-30T04:38:08.075963+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "0248110a1432a6b92f14b898c2685d06911f005297c66d9322763372da503cae", "fetched_at": "2026-08-28T04:04:39.806505+00:00", "kind": "readme", "missing": false, "url": "https://github.com/RythmStick/AMSITrigger"}], "taxonomy_version": 1}, "when_to_avoid": {"confidence": null, "enriched_at": "2026-08-30T04:38:08.075963+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "0248110a1432a6b92f14b898c2685d06911f005297c66d9322763372da503cae", "fetched_at": "2026-08-28T04:04:39.806505+00:00", "kind": "readme", "missing": false, "url": "https://github.com/RythmStick/AMSITrigger"}], "taxonomy_version": 1}, "when_to_choose": {"confidence": null, "enriched_at": "2026-08-30T04:38:08.075963+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "0248110a1432a6b92f14b898c2685d06911f005297c66d9322763372da503cae", "fetched_at": "2026-08-28T04:04:39.806505+00:00", "kind": "readme", "missing": false, "url": "https://github.com/RythmStick/AMSITrigger"}], "taxonomy_version": 1}}, "score": {"components": {"activity": 21, "longevity": 100, "rhythm": 8}, "computed_at": "2026-09-03T02:20:16.233290+00:00", "flags": [], "formula": "round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)", "inputs": {"age_days": 2289, "days_push": 477, "days_rel": 477, "gap_med": null, "n_releases_24m": 1}, "score": 32, "version": 2}, "staleness": {"enrichment_outdated": false, "low_confidence": false, "scrape_days": 9, "stale_scrape": false}}