Suspicious Script Interpreter Network Activity

Detects Python or Node.js processes executing command-line interpreters (e.g., cmd.exe, bash) while simultaneously performing network connections. This behavior is indicative of a post-exploitation activity where an attacker leverages language-specific package paths to execute shell commands and establish command-and-control communication.