PowerShell removes Zone.Identifier ADS to suppress MOTW warnings
Detects the use of PowerShell to remove the 'Zone.Identifier' NTFS Alternate Data Stream from a file, effectively bypassing Mark-of-the-Web (MOTW) security protections. This behavior is often associated with the 'Unblock-File' cmdlet and is used by adversaries to execute downloaded malicious files without security warnings.
Microsoft Sentinel (KQL)

