PowerShell -NoProfile -WindowStyle Hidden -EncodedCommand execution
Detects the execution of PowerShell with suspicious command-line arguments (hidden window, no profile, encoded command) initiated by wscript.exe or mshta.exe. This pattern is commonly used by adversaries to execute obfuscated malicious payloads while proxying the execution through legitimate Windows utilities.
Microsoft Sentinel (KQL)

