GUID-named MSI launched by PowerShell or app spawned from fake Programs folder
Detects suspicious execution patterns involving msiexec where a PowerShell process launches or is the parent of an MSI installation occurring from the %TEMP% directory with a GUID-based filename, or when msiexec executes an application from within %AppData%\Local\Programs. This pattern is often associated with fileless malware, ClickFix-style social engineering attacks, or suspicious persistence/installation behavior.
Sigma

