Execution of PowerShell commands that download files to the %AppData% directory
This rule detects PowerShell processes performing file downloads using common commands (such as Invoke-WebRequest, BITS, or Certutil) and saving or targeting files within user-profile specific directories (AppData). This behavior is often indicative of an adversary staging malicious tools or payloads in a writeable user directory.
Microsoft Sentinel (KQL)

