npm RAT WMI-Based VM Detection via wmic.exe or PowerShell

This rule detects potential discovery activities indicative of a virtual machine or virtualization environment enumeration. It monitors for the execution of wmic.exe or powershell.exe triggered by suspicious parent processes (python.exe, chost.exe) that query hardware-specific identifiers like Manufacturer, Model, or MAC Address using Win32_ComputerSystem or Win32_NetworkAdapterConfiguration.