Apache ActiveMQ Java Spawning Cmd with CertUtil (CVE-2023-46604)

Detects the java.exe (ActiveMQ) process spawning cmd.exe to run certutil for payload delivery. This is highly indicative of CVE-2023-46604 post-exploitation activity, leading to Metasploit and LockBit ransomware deployment.