NeedyMantis Shellcode-as-Script Loader
Detects .ps1-named files dropped to disk that are never actually executed by a PowerShell interpreter (powershell.exe / pwsh.exe) within a short window afterward. NeedyMantis's second-stage loader (e.g. encryptbase64.ps1) is raw x64 shellcode, not a real script -- it's read and executed directly by the dropping process, so no genuine PowerShell host process ever references the file by name. Replaces an earlier version of this rule that watched DeviceImageLoadEvents for a .ps1 extension: Windows can only emit an image-load event for a file with a valid PE header loaded via the OS loader, and raw shellcode has no PE header and is never mapped that way, so that approach would not have fired on this malware. Caveat: legitimate deployment tooling that stages a script for delayed or remote execution can also produce this create/execute mismatch; tune the window and add known-good deployment-tool exclusions for your environment.
Microsoft Sentinel (KQL)

