WM_COPYDATA Injection - Suspicious SendMessage Between Unrelated Processes

This rule detects suspicious inter-process communication (IPC) attempts using WM_COPYDATA messaging, where processes (often script interpreters or unsigned binaries) interact with high-value GUI-based applications (like browsers or shell environments). This pattern is a common indicator of process injection techniques, such as hijacking existing Windows callbacks to execute code within the context of a target process.