Invoke-Obfuscation VAR+ Launcher - PowerShell Module — Detection Rule

Detects Obfuscated use of Environment Variables to execute PowerShell

Read the full analysis on IntelFusions