PowerShell AMSI Bypass: Known Strings, Reflection, or Base64 Patching

Detects execution of PowerShell processes (powershell.exe, pwsh.exe) containing command-line arguments indicative of Antimalware Scan Interface (AMSI) bypass attempts. This includes known bypass strings, reflection-based patching of memory internals (AmsiUtils, GetDelegateForFunctionPointer), and base64-encoded fragments of common bypass techniques.