AMSI Bypass via In-Memory Patching Before Payload Retrieval
This rule detects attempts by a process (specifically targeting PowerShell or .NET loaders) to tamper with Windows Antimalware Scan Interface (AMSI) components in memory. It correlates EDR or Sysmon events (process access, module loads) targeting 'amsi.dll' or involving specific AMSI API strings like 'AmsiScanBuffer' or 'AmsiInitFailed' with potential malicious loader activity.
Splunk (SPL)

