PowerShell Anti-Analysis Enumeration of AV/EDR and VM Artifacts
Detects the execution of PowerShell commands intended to gather system information, specifically targeting the discovery of security software (anti-virus/EDR) and virtualization/sandbox artifacts. This behavior is indicative of an attacker performing environment reconnaissance to identify defensive controls or to determine if the payload is executing within an analysis environment.
CQL

