Suspicious PowerShell Obfuscation and String Manipulation
This rule detects PowerShell commands that exhibit signs of obfuscation by searching for specific string manipulation methods commonly used to hide malicious code. Specifically, it identifies the use of base64 decoding (FromBase64String) or string concatenation combined with character replacement techniques (Replace) on the command line, which are often used by threat actors to execute encoded payloads while bypassing simple string-based signatures.
Microsoft Sentinel (KQL)

