N-central CVE-2026-86218 RCE: suspicious child process/file/network activity

Detects suspicious activity associated with the exploitation of a vulnerability in N-central (CVE-2026-86218). The rule monitors for unauthorized child process spawning by N-central components, creation of files in the application directory consistent with web shells, outbound network connections indicative of command and control, and the creation of new local or service accounts for persistence.