Python.exe executes base64-decoded second-stage payload via -c exec(base64.b64decode)

Detects the execution of Python or Pythonw processes with command-line arguments that include base64 decoding followed by the exec() function. This pattern is commonly used by adversaries to execute obfuscated or encoded malicious code directly in memory to evade detection.