VS Code extension host reads git user.email (developer recon)

This rule detects instances of VS Code, code-server, or associated Node.js processes executing 'git config --get user.email'. This behavior is characteristic of malicious VS Code extensions (specifically 'evil-twin' extensions) attempting to perform developer reconnaissance by harvesting local Git identity information, which can then be exfiltrated.