Suspicious UserAccountBroker Parent Process with Network Connection (ValleyRAT)

Detects UserAccountBroker.exe being spawned by explorer.exe, which is an unusual parent-child relationship. The rule is enriched by looking for subsequent outbound network connections from the UserAccountBroker.exe process, a behavior observed in ValleyRAT infections.