Defender Exclusion Added for Executable in Downloads/Temp (CHOSEN BRICK)

Detects the use of PowerShell to modify Windows Defender exclusions by adding a path or process located in user-controlled directories (Downloads, Temp, AppData). This behavior is characteristic of adversaries attempting to suppress security alerts for malicious binaries masquerading as legitimate software.