T1059.001: Hidden PowerShell Bridge Downloads main.exe via Invoke-WebRequest
Detects suspicious PowerShell execution spawned by common development tools or shell environments like node, npm, or WSL. The rule evaluates the process lineage and scores the command line arguments for characteristics commonly used by malicious payloads, such as hidden execution, bypass flags, network download activity, or temporary file access, which are indicative of software supply chain attacks or automated malicious script execution.
Microsoft Sentinel (KQL)

