IIS Log Command Injection Attempt

Detects multiple attempts at command injection through IIS web server URI queries. The rule looks for common command execution functions like 'eval(', 'system(', or 'exec(' within the 'csUriQuery' field of W3C IIS logs. A threshold of 3 or more attempts from the same IP within an hour triggers the alert.