WSH-spawned PowerShell download cradle staging an installer
This rule detects a suspicious process chain where wscript.exe or cscript.exe (executing a VBScript file) initiates a PowerShell process with arguments typically used for downloading external content (e.g., Invoke-WebRequest, Net.WebClient), followed by subsequent actions involving remote management tools or installation packages (e.g., MSI files, ConnectWise, ScreenConnect, GoToResolve). This behavior is characteristic of initial access or secondary payload delivery via malicious scripts.
Microsoft Sentinel (KQL)

