LNK File Spawns PowerShell as Second-Stage Loader
Detects the execution of PowerShell from a shortcut (.lnk) file, particularly when suspicious command-line arguments such as hidden windows, encoded commands, or bypass flags are utilized. This pattern is commonly associated with initial access via malicious attachments or shortcut files.
SentinelOne

