Encoded PowerShell Loader Chain from ClickFix Google Doc Lure
Detects the execution of PowerShell with hidden window styles and encoded commands that perform common post-exploitation activities, such as remote file downloading or expression evaluation via IEX. This is a common pattern for fileless malware delivery and secondary payload execution.
SentinelOne

