PowerShell AMSI Bypass via Known Patterns or Reflection
Detects attempts to bypass the Antimalware Scan Interface (AMSI) in PowerShell processes. The rule looks for known bypass strings, memory patching via Marshal, reflection-based disabling of AmsiUtils, or base64-encoded AMSI patch targets.
SentinelOne

