Suspicious Wireless Network Enumeration and Profile Modification

This rule detects potentially malicious Wi-Fi network enumeration or profile creation using 'netsh' or 'nmcli', as well as the loading of 'wlanapi.dll' by non-standard, unauthorized processes. Such activities can indicate an attempt by an adversary to discover, connect to, or exfiltrate data via nearby wireless networks.