AMSI/ETW Bypass Patterns in PowerShell ScriptBlock Logs
Detects suspicious PowerShell ScriptBlock logs (Event ID 4104) that attempt to bypass security features like AMSI or ETW while employing common obfuscation techniques such as Base64 encoding, reflection, or character concatenation.
Microsoft Sentinel (KQL)

