Cloudflared service installation via 1.ps1 PowerShell script

Detects the execution or installation of the cloudflared utility via PowerShell, which is often used by adversaries to establish persistence or remote access tunnels (Cloudflare Tunnel). The rule triggers on process command lines involving 'cloudflared' and '1.ps1' keywords commonly associated with scripted deployment.