Chained encoded PowerShell loader downloading secondary payload
Detects a suspicious multi-stage PowerShell execution pattern where an initial process utilizing obfuscated arguments (e.g., -EncodedCommand) launches a secondary PowerShell process that performs network operations indicative of downloading and executing a remote payload.
YARA-L

