PowerShell Test-Path retry loop awaiting dropped file before launch
Detects the execution of PowerShell commands that utilize a combination of 'Test-Path', 'Start-Sleep' (or 'sleep'), and arithmetic obfuscation (e.g., -lt (63+17)). This pattern is often used in malicious scripts to implement a delay while obfuscating the duration, a technique frequently seen in staging or persistence phases to evade sandbox analysis or signature-based detection.
Microsoft Sentinel (KQL)

