PowerShell Fileless Execution via Invoke-Expression
Detects the use of common PowerShell cmdlets often associated with fileless malware execution, such as 'Invoke-Expression', 'IEX', or 'DownloadString', initiated by 'powershell.exe'. These patterns are frequently used to download and execute malicious payloads directly in memory, bypassing traditional disk-based scanning.
Microsoft Sentinel (KQL)

