PowerShell Executing Payload from ProgramData

Identifies PowerShell executing scripts or expressions from the ProgramData directory, which may indicate malicious staging or backdoor execution. This rule specifically looks for PowerShell processes where the command line includes 'C:\ProgramData\' and also contains keywords like 'IEX', 'Invoke-Expression', or '.ps1', suggesting the execution of a script or expression.