QUIETVAULT-Style Infostealer: Non-Interactive Process Spawning Local LLM CLI

This rule detects the invocation of local AI/LLM CLI utilities (e.g., ollama, llama-cpp) by potentially malicious or automated parent processes. It specifically flags scenarios where non-interactive or scripting-based processes (such as WScript, PowerShell, or Python) attempt to use these AI tools, particularly when the command line includes keywords related to sensitive data discovery, such as 'password', 'token', or 'private key'. This behavior is characteristic of infostealer activity (e.g., QUIETVAULT) attempting to use AI tools for automated reconnaissance and credential extraction.