Glossary
Encoded command (-EncodedCommand)
A PowerShell parameter that takes a Base64 string of UTF-16LE command text, used to pass scripts that survive quoting — and to obscure intent.
-EncodedCommand (also -enc, -e) runs a command supplied as Base64 of its UTF-16LE bytes. It legitimately lets a command survive shell quoting, but it is also the most common way to obscure a malicious one-liner. Decode it by Base64-decoding the argument and reading the result as UTF-16LE — a pure text operation that never runs the code.
A common tell is the padded Base64 (VwByAGkAdABlA…), the zero high byte of each ASCII character. Beyond it, attackers add gzip/deflate, [char] codes, concatenation and the -f operator. See decoding encoded commands.