Hidden PowerShell spawned by cplsupport.exe (HiveMQ backdoor)
Detects execution of PowerShell.exe initiated by cplsupport.exe with hidden window styles and non-interactive, no-profile flags, which is often indicative of obfuscated command execution or malicious script activity.
Microsoft Sentinel (KQL)

