Important Detection 2026 – Encoded PowerShell Download Cradle

This rule detects PowerShell processes initiated with command-line arguments that indicate obfuscation (e.g., -enc, -encodedCommand) or attempts to download or execute external content (e.g., IEX, Net.WebClient, Invoke-WebRequest). This pattern is commonly observed during the initial execution of malicious payloads or tool delivery.