Zscaler ZDX - Suspicious Process Detected via Endpoint Telemetry

This rule monitors process execution events and correlates them against a watchlist of known malicious or suspicious binary names, such as crypto-miners, unauthorized remote access tools, or renamed system utilities (LOLBins) being executed from suspicious locations.