Screening Serpens - Fake setup.exe Spawning Discovery Commands

Detects the execution of common system discovery utilities (whoami, ipconfig, net, etc.) by a process named 'setup.exe' originating from suspicious directories such as 'AppData\Local\Temp\' or 'Downloads'. This behavior is often indicative of automated reconnaissance following the initial execution of a potentially malicious installer or dropper.