Input Injection via AutoHotKey, AutoIt3, or xdotool

Detects the execution of AutoHotkey or AutoIt automation scripts, particularly when these tools spawn suspicious child processes (e.g., cmd.exe, powershell.exe, wmic.exe), initiate commands from non-standard directories (Temp, AppData, Downloads), or run from locations outside of the standard Program Files installation directory.