AMSI Bypass via In-Memory Patching - PowerShell/.NET Process

Detects attempts to bypass the Antimalware Scan Interface (AMSI) by monitoring for specific keywords associated with memory patching or tampering within the command lines of PowerShell, .NET-based binaries (dotnet.exe, csc.exe, msbuild.exe), and related processes. The rule specifically looks for strings like 'AmsiUtils', 'amsiInitFailed', and base64-encoded equivalents often used by offensive security tools to neutralize AMSI scanning capabilities.