SHEETCREEP In-Process PowerShell via RunspaceFactory in Non-PowerShell Process

Detects the loading of System.Management.Automation.dll by processes that are not standard PowerShell executables (powershell.exe, pwsh.exe, powershell_ise.exe). This behavior is indicative of in-process PowerShell execution, potentially leveraging techniques like SHEETCREEP's RunspaceFactory.CreateRunspace(). The rule specifically looks for processes loading this DLL from suspicious paths like AppData or if the process is 'vaultsvc.exe', and further filters out cases where a powershell.exe child process is spawned, to reduce false positives.