Encoded PowerShell with Download or Code Execution Indicators

Detects the execution of PowerShell with encoded commands that include signs of web-based downloads or unusually long payloads, which are often used to hide malicious scripts or execute stagers. The rule filters out trusted signers and common administrative management tools to reduce noise.