SnakeBiteAgent lure execution after ZIP extraction

This rule detects the execution of potentially malicious files (executables, scripts) from user-writable directories (Downloads, AppData, Desktop) where the file appears to be related to a ZIP archive recently downloaded or extracted by an archive handler or browser. It correlates process execution events with file creation events from ZIP archives to identify potential user-execution of malicious payloads delivered via ZIP files.