Detects PowerShell scripts to set the ACL to a file in the Windows folder
Read the full analysis on IntelFusions