elastic-protections
high
eql
Powershell Encoded Command
Detects process events where the process is Powershell (pwsh) or a shell interpreter (sh, bash, zsh) with the encoded command flag set in the process arguments. Powershell usage on macOS is extremely rare but usage of Powershell with the encoded command flag, used for executing base64 encoded command strings, is almost always inherently malicious.