AMSI bypass indicators inside injected charmap.exe (AsyncRAT loader)

Detects a suspicious process chain where an AutoIT loader (originating from temporary directories or associated with charmap.exe command line anomalies) executes charmap.exe, followed by the loading of amsi.dll within that charmap.exe process. This behavior is indicative of AsyncRAT injection patterns, specifically where charmap.exe is used as a host process to tamper with AMSI via in-memory patching of AmsiScanBuffer.