Formbook Keylogger - Suspicious Process Access to Keyboard Input APIs via Sysmon CallTrace

This rule detects cross-process memory access events (Sysmon Event ID 10) where a process attempts to hook into keyboard-related Windows API functions such as SetWindowsHookEx, GetKeyState, or GetAsyncKeyState. It further filters for processes executing from suspicious locations (Temp, AppData, ProgramData) or those that are unsigned/unverified, which are common indicators of malicious keylogging or spyware activity.