Suspicious PowerShell Execution from Temp Directory
Detects the execution of PowerShell scripts located in the user's temporary folder. The detection logic looks for common obfuscation flags such as WindowStyle Hidden, NoProfile, and NoLogo, combined with the -File argument, which are frequently used by droppers and malicious payloads to execute scripts in the background while evading immediate user observation.
Microsoft Sentinel (KQL)

