Suspicious Script Interpreter Execution with Network Keywords
Detects the execution of script-based interpreters (wscript.exe, cscript.exe, powershell.exe) where the command line contains keywords typically associated with downloading or executing remote content (http, ftp, download, invoke, execute). This activity is often used in the initial stages of a malware attack to retrieve and run malicious payloads.
Microsoft Sentinel (KQL)

