GIFTEDCROOK - PowerShell Reflective Loader Executing from ProgramData WC3 Path

This rule detects suspicious PowerShell execution patterns involving scripts or payloads stored within specific directory paths (ProgramData\WC3\ or ProgramData\wt1). It flags instances where PowerShell commands include reflective loading techniques ('IEX' or 'Invoke-Expression') while referencing files in these paths, which is often associated with fileless malware execution or malicious loaders.