WSF/VBS Spawns Encoded PowerShell Fetching Vultr Payload
Detects the execution of PowerShell with encoded commands originating from scripting engines wscript.exe or cscript.exe. The command line contains indicators of malicious activity such as references to external domains, archive expansion, or specific executable payloads.
SentinelOne

