Detect any processes that run with LD_PRELOAD environment variable
To learn more about queries, check this guide
SELECT env.pid, env.key, env.value, p.name,p.path, p.cmdline, p.cwd FROM process_envs env join processes p USING (pid) WHERE key='LD_PRELOAD';
PowerShell commands are currently work in progress, contributions welcome.