Most Popular Detection 2026: Encoded PowerShell Command Execution with Obfuscation

This rule detects potentially malicious PowerShell activity by identifying common obfuscation patterns, including encoded commands (Base64), IEX (Invoke-Expression) download cradles, and execution with hidden windows. It triggers when multiple suspicious flags are present or when an unusually long encoded blob is identified in script blocks, command lines, or process arguments.