Obfuscated PowerShell with hidden window running random-named Temp .ps1
Detects the execution of PowerShell scripts located in Windows temporary directories (AppData/Local/Temp or Temp) that utilize common evasion flags such as hidden window style, bypass execution policy, or non-interactive mode. This behavior is frequently associated with initial stagers, droppers, or malicious script execution.
Microsoft Sentinel (KQL)

