conhost.exe --headless Spawning cmd.exe to powershell.exe Chain
Detects a suspicious process chain where 'conhost.exe' with the '--headless' command-line argument spawns 'cmd.exe', which subsequently executes 'powershell.exe'. This pattern is often indicative of automated execution, lateral movement, or malicious script deployment using obfuscated or hidden command-line execution methods.
Cortex XDR

