CLR-Based PowerShell Injection via clr.dll (SloppyRAT PSInline)
Detects instances where a process that is not a known PowerShell host (powershell.exe, pwsh.exe, powershell_ise.exe) loads the System.Management.Automation.dll assembly, which is a strong indicator of an attempt to execute PowerShell code within a different process to evade detection.
SentinelOne

