Whoami as SYSTEM preceded by suspicious SYSTEM shell spawn (ShieldBreak chain)

Detects execution of whoami.exe as NT AUTHORITY\SYSTEM within a short window of, and parented by, a suspicious SYSTEM-privileged shell spawn — a common post-exploitation confirmation step following successful ShieldBreak exploitation. Standalone whoami execution is excluded by design.