wtass.exe spawns cmd.exe for Element backdoor C2 commands
Detects instances where the process wtass.exe (often associated with specific legacy or third-party enterprise tools) spawns cmd.exe. This pattern is potentially indicative of command-line abuse, where a legitimate application's child process is leveraged to execute shell commands.
Microsoft Sentinel (KQL)

