Reflective DLL recon in chrome.exe fingerprints OS/integrity for LPE gating

This rule detects potentially malicious activity where a critical system library like 'kernelbase.dll' is loaded into a Chrome process, followed by events indicative of reflective DLL injection or memory-based code loading. Such behavior is often associated with browser-based exploitation, where an attacker attempts to inject malicious code into the legitimate Chrome process space to maintain persistence or conduct further malicious activities.