SloppyRAT PPID-Spoofed PowerShell (PSSpoof)

Detects instances where PowerShell is launched with explorer.exe as its parent process, but where the child process's metadata (creation time, logon ID, or account SID) does not align with the recorded explorer.exe process. This discrepancy is a strong indicator of Parent Process ID (PPID) spoofing, a technique often used to evade security monitoring.