PowerShell execution of lightlife.ps1 RAT payload from LOCALAPPDATA
Detects the execution of a PowerShell script named 'lightlife.ps1'. The rule flags instances where this specific script is invoked with bypass execution policies or when it is initiated by script hosts like wscript.exe or mshta.exe, which are common patterns for obfuscated or secondary script execution.
Microsoft Sentinel (KQL)

