Detect any processes that run with DYLD_INSERT_LIBRARIES environment variable
To learn more about queries, check this guide
SELECT env.pid, env.key, env.value, p.name,p.path, p.cmdline, p.cwd FROM process_envs env join processes p USING (pid) WHERE key='DYLD_INSERT_LIBRARIES';
PowerShell commands are currently work in progress, contributions welcome.