BeepRAT/DcRAT VM Evasion: WMI Hardware Fingerprinting from Suspicious Path

Detects the execution of wmic.exe with command-line arguments related to hardware enumeration (e.g., system, BIOS, memory, video controller information) which are commonly used by malware for sandbox evasion and VM fingerprinting. The rule specifically alerts when these commands are spawned by processes running from suspicious temporary directories or staging paths often associated with malware droppers.