AMSI patch attempt via AmsiScanBuffer/AmsiScanString memory modification

This rule detects attempts to tamper with the Anti-Malware Scan Interface (AMSI) or suspicious modifications to the memory of common scripting and proxy processes (powershell.exe, pwsh.exe, rundll32.exe, mshta.exe, wscript.exe, cscript.exe). Such activities are often indicative of an adversary attempting to bypass security detection mechanisms to execute malicious code or hide their presence.