C2Looper v2 'ls'/'drives' backdoor command execution

Detects the execution of commands 'ls' or 'drives' via command line, which are often used by threat actors for reconnaissance and file/directory enumeration on a compromised host.