Process reads TOKIO_WORKER_THREADS environment variable during Tokio runtime init

This rule detects potentially malicious behavior where a process accesses environment variables containing 'TOKIO_WORKER_THREADS' (often associated with Rust applications or specific runtime environments) and simultaneously performs sensitive process operations like 'GetSystemInfo' or 'CreateThread'. This pattern may indicate an attempt by an adversary to perform discovery or process injection within a target application environment.