Fileless PowerShell Encoded Command or Execution Policy Bypass
This rule detects potentially malicious PowerShell execution by identifying the use of obfuscated encoded commands or common execution policy bypass flags. It monitors for patterns such as '-EncodedCommand' with long strings, '-ExecutionPolicy Bypass', and other flags typically used to hide PowerShell execution or bypass security restrictions, while excluding trusted Microsoft-signed processes and commands executed from standard system paths.
SentinelOne

