Malware Command Line Keywords

This rule detects the execution of processes where the command line contains keywords commonly associated with malware, specifically 'backdoor', 'rootkit', or 'trojan'. It monitors Windows Security Event ID 4688 (a process creation event) and flags any command lines containing these terms.