PowerShell Spawned from Teams.exe with Suspicious Command-Line
Detects PowerShell or pwsh processes spawned from Teams.exe with command-line arguments indicative of remote download and execution (e.g. Invoke-WebRequest, curl, encoded commands, IEX, Invoke-Expression, Expand-Archive of a zip archive). This pattern matches the TWINLOOT campaign's initial access chain, in which victims are lured via fake Microsoft Teams messages (T1566.004) into launching malicious content that triggers PowerShell execution (T1059.001) from within the Teams process, consistent with user execution of a malicious link or file (T1204.002).
Sigma

