CMSTP UAC Bypass via INF File or /s /au Flags (T1218.003)

Detects the use of cmstp.exe with suspicious command-line arguments (e.g., .inf file references or silent/unattended flags) often associated with bypass of application control or User Account Control (UAC).