# Exception for "Potential Antimalware Scan Interface Bypass via PowerShell"

**URL:** <https://discuss.elastic.co/t/exception-for-potential-antimalware-scan-interface-bypass-via-powershell/378627>\
**Category:** Elastic Security\
**Created:** [May 28, 2025, 7:30am UTC](https://discuss.elastic.co/t/exception-for-potential-antimalware-scan-interface-bypass-via-powershell/378627 "2025-05-28T07:30:03Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![GKre](https://avatars.discourse-cdn.com/v4/letter/g/ecae2f/32.png) [@GKre](https://discuss.elastic.co/u/GKre)\
**Post date:** [May 28, 2025, 7:30am UTC](https://discuss.elastic.co/t/exception-for-potential-antimalware-scan-interface-bypass-via-powershell/378627/1 "2025-05-28T07:30:03Z")

</div>

Hello,

there's a lot of false positives from "Potential Antimalware Scan Interface Bypass via PowerShell". Some of the rules i could find an exception as the script location was part of the message. In this case i could only make an exception for the wholw machine. The script in the message is varying.  
Any idea how to solve this ?

---

<div class="post-metadata">

**Author:** ![Samir\_Bousseaden](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/samir_bousseaden/32/135089_2.png) [@Samir\_Bousseaden](https://discuss.elastic.co/u/Samir_Bousseaden)\
**Post date:** [May 28, 2025, 8:38pm UTC](https://discuss.elastic.co/t/exception-for-potential-antimalware-scan-interface-bypass-via-powershell/378627/2 "2025-05-28T20:38:09Z")

</div>

Hi @GKre, you can open a `Tune Existing Rule` issue [here](https://github.com/elastic/detection-rules/issues) in with a sample event (you can strip off private information such as host and user information etc.) and we can take a looks at it and push a tuning.

For this specific rule we usually use `powershell.file.script_block_text` to tune false positives (if file path is missing) like this exception here [detection-rules/rules/windows/defense\_evasion\_amsi\_bypass\_powershell.toml at bfca0ea4142cb29321ddfc30412963db4e599333 · elastic/detection-rules · GitHub](https://github.com/elastic/detection-rules/blob/bfca0ea4142cb29321ddfc30412963db4e599333/rules/windows/defense_evasion_amsi_bypass_powershell.toml#L135C7-L135C40)

---

<div class="post-metadata">

**Author:** ![GKre](https://avatars.discourse-cdn.com/v4/letter/g/ecae2f/32.png) [@GKre](https://discuss.elastic.co/u/GKre)\
**Post date:** [May 29, 2025, 5:40am UTC](https://discuss.elastic.co/t/exception-for-potential-antimalware-scan-interface-bypass-via-powershell/378627/3 "2025-05-29T05:40:29Z")

</div>

Thank you Samir,  
i opened up an issue #4752

---

<div class="post-metadata">

**Author:** ![GKre](https://avatars.discourse-cdn.com/v4/letter/g/ecae2f/32.png) [@GKre](https://discuss.elastic.co/u/GKre)\
**Post date:** [June 15, 2025, 4:42am UTC](https://discuss.elastic.co/t/exception-for-potential-antimalware-scan-interface-bypass-via-powershell/378627/4 "2025-06-15T04:42:04Z")

</div>

The issue could be fixed by "rule update". It was more or less a lack of knowledge tht the rules need to be updated manually. After updating the rules there's much less alerts and they seem to be more precise. Thanks for the real good support to @Samir_Bousseaden
