PowerShell anti-sandbox VM/security tool enumeration pre-payload
Detects the execution of PowerShell commands initiated from a .lnk file that query system information related to virtualization technologies (e.g., VMware, VirtualBox, Hyper-V) or hardware details (e.g., BIOS, VideoController). This pattern is often used for environmental awareness or anti-sandbox/anti-analysis techniques by malware.
SentinelOne

