PowerShell XOR-decoding of byte arrays before disk write

Detects obfuscated PowerShell commands that utilize XOR operations combined with byte array manipulation and common file writing methods. This pattern is frequently used by malicious scripts to deobfuscate and drop payloads to disk.