Cloudflared service installation via 1.ps1 PowerShell script
Detects the execution or installation of the cloudflared utility via PowerShell, which is often used by adversaries to establish persistence or remote access tunnels (Cloudflare Tunnel). The rule triggers on process command lines involving 'cloudflared' and '1.ps1' keywords commonly associated with scripted deployment.
Microsoft Sentinel (KQL)

