GRAYRABBIT reverse shell: cmd.exe spawned by sideloaded 7z.exe/core.dll

Detects the spawning of cmd.exe from 7z.exe, which is characteristic of the GRAYRABBIT malware sideloading chain where 7z.exe is used to load malicious DLLs (e.g., boy.dll, core.dll) that subsequently initiate an interactive reverse shell.