Signed AutoIT interpreter launched hidden with single dropped script arg

Detects suspicious execution of files located in the AppData Local Temp directory initiated by PowerShell or using PowerShell-specific hidden window arguments. This behavior is commonly associated with dropper scripts or malware staging execution from a user's temporary folder.