Execution of PowerShell commands that download files to the %AppData% directory

This rule detects PowerShell processes performing file downloads using common commands (such as Invoke-WebRequest, BITS, or Certutil) and saving or targeting files within user-profile specific directories (AppData). This behavior is often indicative of an adversary staging malicious tools or payloads in a writeable user directory.