LNK Shortcut Abuse - Startup Persistence or Suspicious Execution via Downloads/Temp
This rule detects the creation of .lnk files in common suspicious directories (such as startup folders, Temp, or Downloads) followed by the execution of common scripting or command interpreters (powershell.exe, mshta.exe, wscript.exe, cmd.exe) with long command lines within a 10-minute window. This behavior is often indicative of an adversary attempting to achieve persistence or execute malicious payloads via user interaction.
Microsoft Sentinel (KQL)

