Fileless PowerShell via COM Object Invocation (T1059.001, T1055)
This rule detects instances where PowerShell or PowerShell Core (pwsh.exe) are spawned as child processes of common COM object host processes (e.g., wscript.exe, mshta.exe, rundll32.exe). The detection specifically looks for command-line arguments containing encoded commands or indicators of download cradles (e.g., IEX, Net.WebClient, DownloadString), which are common patterns for fileless execution and malicious script staging.
SentinelOne

