PowerShell creates SystemIn.lnk persistence shortcut via WScript.Shell (Operation QUICSILVER)
This rule detects PowerShell commands that programmatically create a Windows shortcut (.lnk file) targeting a startup folder or mimicking Windows update processes. This behavior is indicative of an adversary attempting to establish persistence by creating a shortcut that executes a malicious script or binary upon user login or system startup, often associated with the QUICSILVER campaign.
Microsoft Sentinel (KQL)

