APT 35 - Charming Kitten - G0059 — Magic Hound | ScreenConnect service spawning discovery/execution chains

This rule detects suspicious process execution chains originating from ScreenConnect (ConnectWise Control) service. It monitors for common living-off-the-land binaries (LolBins) or specific suspicious command-line patterns (e.g., encoded commands, credential discovery commands) being spawned by the ScreenConnect process, which is often abused by threat actors such as APT35/Magic Hound for remote access and persistence.