PowerShell iex(irm) fileless download-execute from Lightlife C2
Detects suspicious PowerShell command lines that utilize both 'Invoke-Expression' (iex) and 'Invoke-RestMethod' (irm), often used to download and execute code directly from remote sources. The rule specifically monitors for known indicators like specific IP addresses, file paths, or the concurrent use of these cmdlets in a single command line.
Microsoft Sentinel (KQL)

