drop amsi.dll region scan · detect amsi bypass patch bytes · runs locally
scans for AmsiScanBuffer patch bytes · E_INVALIDARG / xor eax ret · amsi string anchors
heuristic screener · parses artifacts locally · not definitive proof