Detects alternate PowerShell hosts potentially bypassing detections looking for powershell.exe
Read the full analysis on IntelFusions