Encoded PowerShell Loader Chain Fetching Multiple Payloads
Detects execution of PowerShell commands using encoded arguments combined with network download cmdlets. This pattern is indicative of a multi-stage loader chain often used in 'ClickFix' style social engineering lures to download and execute secondary malicious payloads.
Sigma

