PowerShell anti-forensics: deleting launch artifacts

This rule detects potentially suspicious file deletion activity originating from PowerShell processes (powershell.exe or pwsh.exe). It monitors for commands targeting temporary directories and specific file extensions (such as .vbs, .lnk, .js, or .ps1) combined with recursive deletion arguments. Additionally, it highlights scenarios where these PowerShell commands are executed by potentially unusual parent processes such as script engines (wscript.exe, cscript.exe, mshta.exe) or other command-line utilities.