PowerShell AMSI Bypass via .NET Reflection - amsiContext/AmsiScanBuffer

Detects the presence of specific keywords within PowerShell Script Block logs (EventCode 4104) that are characteristic of Anti-Malware Scan Interface (AMSI) bypass techniques. These include attempts to manipulate the AMSI context, reflectively load assemblies to modify memory, or force scan failures.