https://www.elastic.co/docs/reference/security/prebuilt-rules/rules/windows/execution_suspicious_powershell_imgload
Suspicious PowerShell Engine ImageLoad | Prebuilt detection rules reference
Identifies the PowerShell engine being invoked by unexpected processes. Rather than executing PowerShell functionality with powershell.exe, some attackers...
detection rulessuspiciouspowershellengineprebuilt