Wscript-spawned Headless conhost.exe Launching Hidden Encoded PowerShell
Detects the execution of PowerShell with suspicious command-line arguments (headless mode, hidden window, encoded commands) spawned by WScript.exe. This pattern is commonly associated with obfuscated script execution or fileless malware staging.
CQL

