Unsigned Process Injecting into System Processes

This rule detects potentially malicious process injection activities where an unsigned or improperly signed process attempts to perform actions like creating a remote thread or opening a process against critical system processes (explorer.exe, svchost.exe), followed closely by the loading of an unsigned module by those same system processes.