Unusual Process Execution with Trust and Authentication Keywords

Detects process executions containing sensitive keywords related to trust, certificates, and multi-factor authentication (e.g., 'mfa', '2fa', 'otp') that are not initiated by standard trusted system processes (services.exe, wininit.exe, smss.exe). This pattern is often indicative of credential manipulation, certificate harvesting, or tampering with authentication mechanisms.