Because malicious PowerShell use often looks like legitimate, CrowdStrike doesn’t limit the amount of visibility when it comes to PowerShell.
Many vendors claim they can identify details when PowerShell is used in an attack, and that’s very important, but it is also limiting.
Falcon PowerShell Visibility 3 Different Ways to Investigate PowerShell Activity