C2Looper 'run' command spawning cmd.exe from unusual parent process
This rule detects the execution of 'cmd.exe' when it is spawned by a process that is not part of a common list of authorized parent processes. This behavior is often indicative of potential malicious activity, as adversaries may attempt to spawn shells from unexpected applications to maintain persistence, execute secondary payloads, or perform lateral movement.
Microsoft Sentinel (KQL)

