PowerShell child process spawned from msvcp150/160.dll-loaded host process

Detects instances where PowerShell.exe is launched by a process that has loaded specific Visual C++ Redistributable DLLs (msvcp150.dll or msvcp160.dll). This pattern is often associated with the execution of applications built with Visual Studio 2017/2019 that may be acting as loaders or wrappers for malicious PowerShell scripts.