Suspicious PowerShell Download Cradle Execution

Detects the use of PowerShell to download content from an external URL and immediately execute it in memory using common download cradles (e.g., Net.WebClient, IWR) combined with execution commands like IEX (Invoke-Expression). This is a common pattern for fileless malware delivery and post-exploitation activity.