PowerShell Encoded Command Execution
This rule detects the execution of PowerShell or pwsh.exe with an encoded command. Adversaries often use encoded commands to obfuscate their malicious scripts and evade detection. The rule specifically looks for the '-EncodedCommand' or '-enc' parameter followed by a base64-encoded string of at least 20 characters.
Microsoft Sentinel (KQL)

