Encoded or Obfuscated PowerShell Execution
Detects suspicious PowerShell command-line activity involving the use of encoded, obfuscated, or stealth-focused flags, as well as common patterns associated with fileless payload delivery and execution.
Sigma

