Microsoft Outlook Spawning Suspicious Child Processes

Detects instances where Microsoft Outlook (OUTLOOK.EXE) initiates common living-off-the-land (LotL) binaries that are often abused by malicious attachments or macros to execute secondary commands, such as PowerShell, command prompt, or script host engines.