Suspicious Script Deployment into ProgramData
Identifies the creation of PowerShell or batch files in unusual ProgramData subdirectories by command-line interpreters, which may indicate malware staging or persistence preparation.
Microsoft Sentinel (KQL)

