Potential Webshell process spawn correlated with web-directory file drop

This rule detects potential webshell activity by monitoring the correlation between web server processes spawning suspicious child processes (e.g., cmd.exe, powershell.exe, rundll32.exe) and the creation of executable or script files within identified web directories. The logic establishes a high-confidence correlation when both events occur on the same device within a 15-minute window, while also surfacing uncorrelated individual process spawns or suspicious file writes as lower-confidence indicators. It includes exclusions for known administrative and deployment processes to reduce noise.