Unsigned Executable Launch Followed by SYSTEM whoami Confirmation

Detects the execution of an unsigned binary under a non-SYSTEM user context that directly spawns 'whoami.exe' which then runs as the SYSTEM account. This behavioral pattern is indicative of a successful local privilege escalation exploitation, where a malicious binary confirms its escalation by querying the current user identity in a SYSTEM shell. The rule includes exclusions for common administrative agents, such as the Microsoft Intune Management Extension, that may exhibit similar behavior due to periodic detection scripting.