With the common use of powershell by cobalt strike and every other threat actor, I though it would be nice to have a query that detects and decodes encoded powershell commands.
The first query will simply decode base 64 encoded data (As you would see...