SloppyRAT PSInline In-Process PowerShell via CLR/COM Injection
Detects instances where processes other than legitimate PowerShell binaries load the .NET Common Language Runtime (clr.dll) or the System.Management.Automation assembly. This behavior is often indicative of 'PowerShell-less' execution techniques, where adversaries interact with the PowerShell engine directly from arbitrary host processes to execute malicious code or scripts.
Cortex XDR

