cmd.exe spawns PowerShell with ExecutionPolicy Bypass

Detects instances where cmd.exe spawns a powershell.exe process with the execution policy set to bypass. This is a common technique used by attackers to execute malicious scripts while bypassing local security restrictions on script execution.