UAC elevation of hidden encoded PowerShell via ShellExecute runas

Detects the execution of PowerShell with obfuscation-related flags (-NoProfile, -WindowStyle Hidden, -EncodedCommand) initiated by common scripting interpreters (wscript.exe, mshta.exe, cscript.exe). This pattern is often indicative of malicious scripts, such as HTA or VBScript files, attempting to execute encoded PowerShell commands in a high-privilege context.