PowerShell In-Memory Loader Using Byte Reversal

Detects PowerShell commands that reverse byte arrays before dynamically loading assemblies into memory, a behavior commonly associated with advanced malware loaders and fileless execution techniques. The rule specifically looks for PowerShell process command lines containing 'IO.File', 'System.Reflection.Assembly', 'Length-1', and '..0', which are indicative of byte array manipulation and in-memory assembly loading.