Renamed Powershell Under Powershell Channel — Detection Rule

Detects a renamed Powershell execution, which is a common technique used to circumvent security controls and bypass detection logic that's dependent on process names and process paths.

Read the full analysis on IntelFusions