LausivLoader wscript->conhost--headless->PowerShell EncodedCommand chain
Detects a suspicious execution chain where WScript.exe initiates a process with '--headless' arguments, which in turn spawns a PowerShell process with hidden, encoded, and non-interactive command line flags. This pattern is commonly used by adversaries to execute malicious scripts while attempting to evade detection and user interaction.
Splunk (SPL)

