API Hooking Command Line Activity

Detects command-line activity containing keywords related to API hooking (e.g., SetWindowsHookEx, hook, inline, trampoline) initiated by common scripting interpreters like powershell.exe, cmd.exe, or rundll32.exe. This pattern is often associated with malware attempting to inject code or capture data by intercepting process function calls.