The issue I have encountered is that when en extremely long Base64 encoded Powershell script hits this query, the query returns only a small portion of the end of the results. Upon debugging the regex and trying out different variations I noticed that in the Powershell commandline the Base64 portion is actually divided into 64 character segments with a space in between them. I assume this is due to the commandline looking nicer if you hover over it in the web console. However, after I modified my regex to include these spaces the results still were the same. Only the last of those 64 character segments matched.
The query does work sometimes as apparently there is some limit after which that 64 character division happens. This leads me to believe that there might some sort of bug in MDE itself that prevents the query from matching the correct group.
If anyone else has encountered this sort of behavior or sees any errors in my logic all input is welcome! Otherwise I would file this as a bug but unfortunately I was not able to locate where MDE related bugs could be submitted.