Suspicious LNK-Spawned cmd.exe with Obfuscated Substring Expansion
Detects the execution of cmd.exe spawned by explorer.exe that contains suspicious command line parameters. The rule specifically targets the use of obfuscated Windows batch substring expansion (e.g., %VAR:~0,1%) or commands being executed directly from common user-writable directories like Temp or Downloads, which are common indicators of malicious LNK file abuse.
Sigma

