UAC Elevation via ShellExecute 'runas' to Launch Hidden PowerShell
Detects the execution of PowerShell with hidden window styles and encoded commands, initiated with High Integrity (Admin) privileges. This pattern is often indicative of bypasses for User Account Control (UAC) or malicious script execution where an adversary attempts to run elevated code while minimizing user visibility.
Sigma

