Suspicious Process Injection from System Processes to Scripting Engines

This rule detects suspicious process creations where common system processes (svchost.exe, explorer.exe, lsass.exe, winlogon.exe) act as parent processes for scripting or command-line interpreters (powershell.exe, cmd.exe, cscript.exe, wscript.exe) and the child process runs with a low or untrusted integrity level. This pattern can indicate process injection or other forms of malicious execution where an attacker attempts to hide their activity by masquerading as legitimate system processes.