AdaptixC2 - SSH Reverse Tunnel C2 Channel Establishment

Detects potential SSH reverse tunneling or SOCKS proxying, often used by threat actors like Akira or associated with Bumblebee loaders, to establish persistent C2 channels. The rule monitors process execution of plink.exe and ssh.exe with suspicious arguments (e.g., -R, -D, -N), network connections to known malicious C2 IP addresses, and SSH tunnel processes running as SYSTEM or spawned by non-interactive service-related processes.