PowerShell reverse shell/RAT with hidden encoded IEX and persistent outbound socket
Detects the execution of PowerShell with suspicious command-line arguments (hidden window, encoded commands using char arrays, and iex) that subsequently initiates multiple or long-running network connections. This behavior is indicative of a remote access trojan, beaconing, or fileless malware downloading additional payloads.
Microsoft Sentinel (KQL)

