PowerShell execution with encoded/base64 command arguments
Detects the execution of PowerShell with encoded commands, a common technique used by attackers to obfuscate malicious scripts and evade detection.
Microsoft Sentinel (KQL)

Detects the execution of PowerShell with encoded commands, a common technique used by attackers to obfuscate malicious scripts and evade detection.

Already have an account?