PowerShell Reflective .NET Assembly Load via Reflection.Assembly::Load

Detects the use of PowerShell to load .NET assemblies directly from memory or via Base64/encoded streams. This technique is commonly used by malicious payloads to execute shellcode, reflection-based attacks, or obfuscated scripts while minimizing their on-disk footprint.