Title:Suspicious FromBase64String Usage On Gzip Archive - Process Creation Status:test Description:Detects attempts of decoding a base64 Gzip archive via PowerShell. This technique is often used as a method to load malicious content into memory afterward. References: -https://speakerdeck.com/heirhabarov/hunting-for-powershell-abuse?slide=43 Author: frack113 Date: 2022-12-23 modified:None Tags: