Unauthorized Remote Access Tool Deployment

Detects the execution of known Remote Monitoring and Management (RMM) and remote access tools. The rule specifically flags these tools when they are executed from high-risk directories such as AppData, Temp, Downloads, or ProgramData, which is a common indicator of unauthorized installation or persistence efforts by an adversary.