LausivLoader PowerShell AES-decrypt & reflective .NET assembly load

This rule detects PowerShell script blocks that exhibit multiple indicators of obfuscation and in-memory execution. It identifies the combination of AES encryption, embedded key bytes commonly associated with deobfuscation routines, GZip compression, and reflective assembly loading (Assembly.Load). The use of multiple techniques simultaneously significantly increases the likelihood of malicious activity, such as fileless malware loading or execution of obfuscated payloads.