FalconFlank: CrowdStrike Falcon Macro-Remediation DLL Sideload LPE

Detects potential exploitation of a CrowdStrike Falcon remediation process vulnerability ('FalconFlank'). The rule identifies either direct execution of the PoC binary or the suspicious combination of a CrowdStrike remediation process loading an unsigned or untrusted DLL from a user-writable path followed by the same process spawning a command shell in the SYSTEM context within 15 minutes.