BRICKSTORM Backdoor Pattern - Non-Interactive Beaconing with Credential File Access

Detects a network-connected Linux process exhibiting beaconing behavior (high-frequency external connections) that is subsequently correlated with unauthorized file access to sensitive Linux configuration files (/etc/passwd, /etc/shadow, or authorized_keys). This rule filters out common system processes and standard management binaries, targeting suspicious command-and-control activity combined with credential theft.