LoaderClient/WeedHack CMSTP UAC Bypass via Crafted INF File (T1548.002)

Detects execution of the Microsoft Connection Manager Profile Installer (cmstp.exe) when initialized with an INF file from potentially suspicious directories (e.g., Temp, AppData), or when cmstp.exe is observed spawning common command-line shells (cmd.exe, powershell.exe) or rundll32.exe, which is indicative of potential proxy execution or UAC bypass techniques.