Glossary
Execution policy bypass
Flags such as -ExecutionPolicy Bypass that turn off PowerShell's script-running safety check — a near-ubiquitous marker in malicious launchers.
PowerShell's execution policy is a safety setting that controls whether scripts may run; it is not a security boundary. Malicious launchers routinely disable it for one session with -ExecutionPolicy Bypass (or -ep bypass, -ExecutionPolicy Unrestricted), often alongside -NoProfile and -WindowStyle Hidden.
On its own an execution-policy bypass is not proof of malice — automation uses it too — but combined with a hidden window, an encoded command or a download cradle it is a strong signal. This parser flags the bypass, hidden windows and log/history clearing. See the event-log guide.