Woodgnat CrashFix/FileFix Teams Lure PowerShell Download Cradle

This rule detects instances where Microsoft Teams (Teams.exe or ms-teams.exe) initiates a PowerShell process (powershell.exe or pwsh.exe) with command-line arguments typically associated with malicious activity, such as downloading content from the internet, executing encoded commands, or utilizing scripting shortcuts (e.g., IEX, curl). This behavior may indicate an attempt to achieve code execution through compromised collaboration tools.