IronPython Executes zlib/Base64-Encoded Python Stager
Detects the execution of IronPython or generic Python interpreters where the command line contains suspicious obfuscation patterns, including base64-encoded strings, zlib compression/decompression, and the use of the subprocess module. This pattern is commonly used by adversaries to execute hidden or obfuscated malicious payloads.
SentinelOne

