Outbound HTTP GET for shell.ps1 second-stage PowerShell payload

This rule detects outbound HTTP GET requests initiated by a process using a 'WebClient' user-agent to retrieve a file named 'shell.ps1'. This behavior is characteristic of adversaries downloading second-stage PowerShell payloads to a compromised host.