T1059.001 (PowerShell), T1105 (Ingress Tool Transfer)
This rule detects potentially malicious PowerShell activity characterized by the co-occurrence of file download indicators (such as Invoke-WebRequest, WebClient, or UserAgent strings) and file execution or staging commands (such as IEX, Expand-Archive, or Copy-Item) within the same command line. It is designed to identify ingress tool transfer and command-line execution patterns often associated with post-exploitation or malware staging, while reducing noise by requiring both download and operational intent.
Microsoft Sentinel (KQL)

