PowerShell Base64 reassembly with junk-char stripping before decode
Detects the use of obfuscated PowerShell commands that utilize .NET [Convert]::FromBase64String combined with character replacement string manipulation, a common technique to hide malicious payloads from simple static analysis.
Microsoft Sentinel (KQL)

