Suspicious Process Execution via MMC or Explorer

This rule detects the execution of potentially malicious processes (cmd.exe, powershell.exe, wscript.exe, cscript.exe, mshta.exe, rundll32.exe) initiated by mmc.exe or explorer.exe, excluding known legitimate Microsoft Management Console (MMC) flags and common management snap-ins. This pattern is indicative of potential proxy execution or misuse of system administration utilities to run unauthorized code.