LNK File Spawns PowerShell to Continue Infection Chain

Detects the execution of PowerShell with suspicious command line flags (such as hidden windows, bypass execution policies, or encoded commands) where the parent process is a shortcut (.lnk) file. This is a common technique used by attackers to execute malicious scripts via phishing or social engineering, where a user is tricked into clicking a malicious link file.