https://mustafanafizdurukan.github.io/posts/investigating-suspicious-powershell-execution/
Investigating a Suspicious PowerShell Script Execution - Mustafa Durukan