OT Infrastructure Attack - Dropbear SSH Installed for Remote Access on ICS Host

Detects the execution of Dropbear SSH binaries (dropbear, dropbearkey, dropbearmulti) on identified OT, ICS, or SCADA assets. The rule flags suspicious configurations such as the use of non-standard ports (2222, 44818), remote port forwarding, or running in the foreground, which may indicate unauthorized remote access or tunneling on sensitive operational technology infrastructure.