This query will search the Data Lake for all encoded PowerShell that has been run
WITH encoded_data AS (
SELECT
calendar_time,
name,
username,
meta_hostname,
sophos_pid,
cmdline,
parent_name,
parent_sophos_pid,
query_name,
replace(substr...