Kimsuky guide.url.lnk spawning PowerShell loader
Detects the execution of PowerShell with encoded commands or Base64 decoding attempts initiated by common Windows shell applications (explorer, mshta, wscript, cscript) launched from an LNK file. This pattern is commonly associated with malicious LNK shortcuts used as initial access vectors or stage-two downloaders.
Microsoft Sentinel (KQL)

