Unprivileged User Namespace Creation on Linux

This rule detects the creation of user namespaces on Linux systems by unprivileged users. The 'unshare' command with '--user' or '-U' flags allows a process to move into a new user namespace, which can be abused for privilege escalation or container escape. The rule specifically excludes common container runtimes and processes running as 'root' to reduce false positives.