PowerShell Script Run in AppData — Detection Rule

Detects a suspicious command line execution that invokes PowerShell with reference to an AppData folder

Read the full analysis on IntelFusions