Conhost Headless Execution via Pcalua (GOLD BLADE’s)
Detects the execution of 'conhost.exe' with the '--headless' argument, specifically when initiated by 'pcalua.exe'. This combination has been observed in attacks by the GOLD BLADE threat group for indirect command execution.
Microsoft Sentinel (KQL)

