Windows Shell or Script Execution From IIS Directory — Detection Rule
Detects Windows command tools such as cmd, PowerShell, or pwsh being executed from the IIS installation directory. This can be indicative of exploitation of software reliant on IIS such as Exchange.