macOS Gaslight - Prompt Injection Strings Detected in Binary Execution

This rule monitors process command lines and file activity for keywords associated with potential reconnaissance, error logs, or debugging artifacts often used during post-exploitation or system profiling. It flags commands or files containing terms like 'memory dump', 'stack trace', 'SQL injection', or 'Redis failure', which may indicate an attacker analyzing system information or attempting to interact with backend services.