Suspicious Process Injection Indicators in Command Line

Detects command-line activity containing keywords associated with process injection or hollowing techniques (e.g., shellcode, inject, hollow, replace) when executed by common script interpreters targeting critical system processes.