LNK-Triggered PowerShell Tunnel Deployment

Detects suspicious PowerShell execution initiated by explorer.exe, specifically when the command line includes a .lnk file, execution policy bypass, and contains keywords or paths commonly associated with malicious activity (e.g., tor, ssh, github.io, dropbox.com, or suspicious temporary/public directories). This pattern is often observed in initial access or execution phases of attacks.