Living-off-the-land-to-evade-detection Queries and Alert setup

hi guys, just need a bit of your help with configuring queries to detect those sneaky command line execution then setup alert rule based on that. Thanks :slight_smile: