Detects encoded PowerShell - classic LOLBIN

Detects the execution of PowerShell or PWSH with command-line arguments often used to obfuscate scripts or hide activity, such as encoded commands (-enc), base64 decoding, or running the process with a hidden window.