ClickFix Win+R hidden-window encoded PowerShell execution
Detects execution of PowerShell processes using the '-w hidden' argument and '-enc' (EncodedCommand) parameter, which is a common technique used by attackers to execute obfuscated code silently.
SentinelOne

