PowerShell Launched with Encoded Command Argument

Detects instances of PowerShell or PowerShell Core (pwsh) launched with encoded command line arguments (-encodedcommand, -enc, -ec). This is a common technique used by attackers to obfuscate malicious scripts and payloads by passing them as Base64 encoded strings to avoid simple static analysis.