Bird Agent Backdoor: Hidden PowerShell/CLI Command Execution
Detects the execution of powershell.exe or cmd.exe with a combination of -NonInteractive, -NoProfile, and -Command arguments. This combination is frequently used by adversaries to execute scripts or commands stealthily, without user interaction or loading profile configuration files, which is a common behavior during the execution phase of an attack.
CQL

