Most Popular Detection 2026: Encoded and Obfuscated PowerShell Execution

Detects suspicious PowerShell process creation patterns often associated with malicious activity. The rule identifies PowerShell execution invoked by common parent processes (like Office applications or scripting engines) or using highly suspicious command-line arguments such as encoded commands, hidden windows, or common download and execution patterns (e.g., IEX, WebClient).