Most Popular Detection 2026 – LLM Agent Prompt-Injection PowerShell Download Cradle (Network)
Detects outbound HTTP GET requests where the user agent is set to 'WebClient' and the URI ends in '.ps1'. This behavior is characteristic of PowerShell download cradles, which are often used by adversaries to fetch and execute remote malicious scripts directly into memory.
Suricata

