AMSI Bypass Attempt via PowerShell Script Block Logging
Detects attempts to bypass or tamper with the Antimalware Scan Interface (AMSI) in PowerShell by monitoring for common bypass techniques such as reflective loading of AmsiUtils, tampering with the amsiInitFailed field, or memory patching of AmsiScanBuffer via Script Block Logging (EventID 4104).
Splunk (SPL)

