XOR-Based PowerShell Payload Decryption

Detects PowerShell commands using XOR operations together with execution primitives that may indicate obfuscated in-memory payload decoding. Specifically looks for 'powershell.exe' executing with '-bxor', '81', and either 'IEX' or 'Invoke-Expression' in the command line.