Script Staging in ProgramData Directory
Detects the creation of PowerShell or batch scripts within the C:\ProgramData directory, which is a common location abused by malware for payload staging and persistence. The rule specifically looks for file creation events where the initiating process is cmd.exe or powershell.exe and the file extension is either .ps1 or .bat.
Microsoft Sentinel (KQL)

