Hidden PowerShell Base64 Invoke-Expression staging JSCeal downloader
Detects the execution of PowerShell commands that utilize base64-encoded strings, window style arguments for obfuscation, and subsequent decoding to reveal suspicious indicators such as network downloading commands or archive manipulation, indicative of potential fileless malware staging.
Microsoft Sentinel (KQL)

