Suspicious Encoded PowerShell or CMD Execution
Detects suspicious process execution patterns involving PowerShell with encoded commands or CMD with command execution flags. The rule looks for multiple occurrences of these patterns from the same computer and account within a one-hour window, which could indicate malicious activity such as script execution or obfuscated command execution.
Microsoft Sentinel (KQL)

