Exploit-Related Artifact Detection in Process Command Line
This rule detects process execution where the command line arguments contain keywords commonly associated with memory corruption and exploitation (e.g., shellcode, buffer overflow, heap/stack manipulation). The rule further filters for small executable files (less than 100KB) to increase the likelihood of identifying malicious tools or stagers.
SentinelOne

