APT28 NotDoor OneDrive.exe Spawning Encoded PowerShell via SSPICLI Sideload

Detects instances where PowerShell.exe is launched by the OneDrive synchronization process, potentially indicating an attempt to mask malicious command execution as a legitimate cloud storage process.