Process Hollowing: Legitimate Windows Process Spawning Unexpected Shell (T1055.012)

Detects instances where common Windows processes (svchost.exe, explorer.exe, or notepad.exe) spawn suspicious child processes (such as cmd.exe, powershell.exe, or wscript.exe). The rule identifies potential process hollowing or living-off-the-land techniques by correlating parent-child relationships with suspicious command-line parameters (encoding, hidden execution, or in-memory execution) or anomalous file paths (running from user-writable directories).