PowerShell Hardware Fingerprinting
Detects PowerShell queries for motherboard serial numbers or UUIDs, behaviors commonly associated with malware reconnaissance and sandbox evasion. This rule specifically looks for 'powershell.exe' executing commands that query 'Win32_BaseBoard' or 'Win32_ComputerSystemProduct' and contain 'SerialNumber' or 'UUID'.
Microsoft Sentinel (KQL)

