PowerShell Payload Download with Token Authentication

Detects the use of PowerShell (Invoke-WebRequest or Invoke-RestMethod) to download files to the AppData directory, followed by the execution of a file using a 'token-raw' argument. This pattern is often associated with malicious payload delivery and execution.