Suspicious PowerShell/CMD Execution Linked to Bot Interaction Keywords
Detects the execution of command interpreters (PowerShell, CMD, WindowsTerminal) spawned by common user-facing applications (Explorer, WindowsTerminal, DLLHost) where the command line arguments contain keywords associated with automated human verification (e.g., CAPTCHA, bot detection) and suspicious download/execution patterns (e.g., iex, base64). This behavior is characteristic of malicious automated scripts or malware attempting to bypass security challenges via interactive shells.
CQL

