CRPx0 ClickFix: Hidden-Window Encoded PowerShell Stager via WindowsUpdate.log

Detects execution of PowerShell commands that utilize hidden window styles and encoded payloads, specifically when the command line or image path references 'WindowsUpdate.log'. This pattern is often used by adversaries to hide malicious scripts and potentially interact with logs in an attempt to masquerade or tamper with Windows Update processes.