Malicious Supply Chain Package Execution - Scripting Engine Spawning Shell
This rule detects potentially malicious software supply chain attacks by identifying suspicious child processes spawned by package managers (pip, npm) or Python scripting engines within a short timeframe. It specifically looks for shells (cmd, powershell, bash, etc.) being invoked immediately after a package installation or script execution, and correlates this activity with suspicious outbound network connections originating from these processes.
Microsoft Sentinel (KQL)

