BeepRAT UAC Bypass - COM Surrogate Spawning Child Process from User-Writable Path

Detects potential UAC bypass attempts using COM surrogate (dllhost.exe) or MMC (mmc.exe) to spawn child processes from suspicious or user-writable locations like AppData or Temp. It also monitors for specific command-line artifacts associated with BeepRAT and other potentially malicious activity.