PowerShell Encoded/Obfuscated Command Execution (T1059.001)

Detects execution of PowerShell processes employing common obfuscation and evasion techniques frequently associated with fileless malware loaders and malicious script execution. This includes the use of EncodedCommand, Base64 strings, IEX/Invoke-Expression download cradles, and stealth execution flags (e.g., hidden windows combined with non-interactive modes).