Rule should be focusing on the 'process_command_line' field and not just on any value of any event generated by powershell.exe. SIGMA HELK standardization config updated to match latest HELK Common Information Model