SYSTEM-privileged cmd.exe spawned as ShieldBreak exploit terminal step

Detects instances where cmd.exe is executed within the context of the 'NT AUTHORITY\SYSTEM' account, but the parent process was not initiated by a SYSTEM account. This behavior is often indicative of privilege escalation where an adversary leverages a service or process to execute commands with elevated privileges.