Process injection chain targeting charmap.exe via remote thread creation

Detects a suspicious process injection chain (OpenProcess, VirtualAllocEx, WriteProcessMemory, CreateRemoteThread) targeting the Windows Character Map utility (charmap.exe) located within the SysWOW64 directory. This activity is often used by adversaries to execute malicious code within a legitimate, signed process context to evade security monitoring.