Obfuscated PowerShell with encoded flags and download cradle
Detects the execution of PowerShell with suspicious command-line flags (EncodedCommand, NoProfile, WindowStyle Hidden, ExecutionPolicy Bypass) combined with either potential Base64-encoded payloads or network-based download cradles (e.g., Invoke-Expression, WebClient).
Splunk (SPL)

