Suspicious Usage of For Loop with Recursive Directory Search in CMD (2782fbd8-b662-4eb5-9962-5bfbfb671e7b)
Detects suspicious usage of the cmd.exe 'for /f' loop combined with the 'tokens=' parameter and a recursive directory listing. This pattern may indicate an attempt to discover and execute system binaries dynamically, for example powershell, a technique sometimes used by attackers to evade detection. This behavior has been observed in various malicious lnk files.