PowerShell IRM Download Cradle via RunMRU

Detects the inclusion of PowerShell download commands ('irm' or 'Invoke-RestMethod') within the Windows 'RunMRU' registry key. This key is used by Windows Explorer to track recently typed run commands, and adversaries often abuse it to maintain persistence or store malicious one-liner payloads that are intended to be executed at a later time.