Obfuscated or Encoded PowerShell Execution (T1059.001)

Detects the execution of PowerShell with suspicious command-line patterns indicative of obfuscation or malicious intent, including encoded commands, Base64 decoding, IEX combined with common download cmdlets, and specific obfuscation techniques like backtick concatenation, character casting, or variable concatenation.