T1059.001
Running malicious PowerShell commands and scripts, often in memory to evade disk-based detection.