Suspicious PowerShell execution
Look beyond process names to encoded content, parent-child relationships, and network behavior.
Brief overview
Useful pivots include EncodedCommand, IEX, hidden window flags, browser or Office parents, and connections immediately after launch.