Detect Arbitrary Command Execution Using WSL

This rule detects the execution of arbitrary commands via the Windows Subsystem for Linux (WSL) by monitoring process creation events where 'wsl.exe' is the executable. It specifically looks for command lines that include flags like '--exec' or '-e', or common shell commands and downloaders such as 'curl', 'wget', 'bash -c', 'sh -c', 'nc ', or 'ncat '. This activity can indicate an adversary leveraging WSL to execute malicious code or bypass security controls.