PowerShell Script Obfuscation Detected via Character Array Joining
This rule detects PowerShell commands that utilize specific character array joining techniques (e.g., [char]nnnn -join '') often used to obfuscate malicious strings or bypass keyword-based security filters. This is a common tactic for evading detection when downloading or executing payloads.
Microsoft Sentinel (KQL)

