Tag
This detection analytic identifies suspicious PowerShell activity by monitoring command-line strings for patterns associated with known offensive security toolkits used for credential theft, lateral movement, and persistence.