Suspicious PowerShell Download Cradle Execution
Detects the use of PowerShell to download content from an external URL and immediately execute it in memory using common download cradles (e.g., Net.WebClient, IWR) combined with execution commands like IEX (Invoke-Expression). This is a common pattern for fileless malware delivery and post-exploitation activity.
Sigma

