WhatsApp Desktop Spawning Suspicious Scripting Processes

This rule detects instances where the WhatsApp Desktop application (WhatsApp.exe) spawns suspicious child processes commonly used for scripting or command execution, such as wscript.exe, cscript.exe, powershell.exe, cmd.exe, or rundll32.exe. It specifically excludes known legitimate update and service-related command lines to reduce false positives. This behavior could indicate a phishing attempt or malware execution originating from a compromised WhatsApp session.