Renamed Powershell Under Powershell Channel (30a8cb77-8eb3-4cfb-8e79-ad457c5a4592)
Detects a renamed Powershell execution, which is a common technique used to circumvent security controls and bypass detection logic that's dependent on process names and process paths.