Windows Shell or Script Execution From IIS Directory — Detection Rule

Detects Windows command tools such as cmd, PowerShell, or pwsh being executed from the IIS installation directory. This can be indicative of exploitation of software reliant on IIS such as Exchange.

Read the full analysis on IntelFusions