elastic
high
kql
Long Base64 Encoded Command via Scripting Interpreter
Identifies oversized command lines used by Python, PowerShell, Node.js, or Deno that contain base64 decoding or
encoded-command patterns. Adversaries may embed long inline encoded payloads in scripting interpreters to evade
inspection and execute malicious content across Windows, macOS, and Linux systems.