Monitor PowerShell hosts with WMI
This snippet alerts whenever a PowerShell host process is started; the detection technique is the same one discussed in Query PowerShell alternative hosts with WMI and Alternate PowerShell Hosts.
References:
Last updated