WMI XSL Script Processing via wmic /format or msxsl.exe (T1220)

This rule detects the use of 'wmic.exe' with the '/format' switch to execute XSL files, or the direct execution of 'msxsl.exe'. These methods are common techniques used by adversaries to bypass security controls by executing arbitrary scripts embedded within XSL files, often fetched from remote locations or local paths.