PowerShell Script Writing Obfuscated Bytes to Disk
Detects PowerShell command execution that uses bitwise XOR operations combined with the .NET [IO.File]::WriteAllBytes method. This pattern is commonly used by malware, such as AsyncRAT, to deobfuscate and drop secondary payloads or modules onto the file system during execution.
Microsoft Sentinel (KQL)

