Suspicious Process Command Line Keywords Indicating Potential Malware

This rule monitors process command line arguments for a combination of programming language interpreters (java, python, node, .NET, go) and keywords commonly associated with malware, payloads, shellcode, or injection techniques. This is intended to identify suspicious execution patterns that may indicate the staging or execution of malicious code.