Glossary
Invoke-Expression (IEX)
A PowerShell cmdlet that runs a string as code — the execution half of most download cradles and obfuscation chains.
Invoke-Expression (alias IEX) evaluates a string as a PowerShell command. It is the execution step that turns a decoded or downloaded string into running code, so it appears at the end of most download cradles and obfuscation chains (IEX $decoded, & ([scriptblock]::Create($s))).
Legitimate uses exist but are rare in day-to-day administration, so IEX applied to a downloaded or decoded string is a strong triage signal. This parser flags Invoke-Expression and [scriptblock]::Create and, when paired with a download, raises it to a download-cradle finding. See decoding encoded commands.