Kimsuky PowerShell loader anti-analysis VM/security-tool checks

This rule detects the execution of PowerShell commands that simultaneously perform reconnaissance for security analysis tools and virtual machine environment indicators. The presence of encoded, hidden, or non-interactive PowerShell flags in conjunction with these discovery actions is indicative of an adversary attempting to verify their execution environment to evade detection and analysis by security researchers or automated sandbox systems.