elastic
high
kql
Potential PowerShell Obfuscation via Character Array Reconstruction
Detects PowerShell scripts that reconstructs strings from char[] arrays, index lookups, or repeated ([char]NN)+
concatenation/join logic. Attackers use character-array reconstruction to hide commands, URLs, or payloads and evade
static analysis and AMSI.