Casbaneiro process injection into RegSvcs.exe or mobsync.exe

Detects instances where processes associated with AutoIt scripting (e.g., AutoIt-based compiled executables or scripts) initiate suspicious API calls including CreateRemoteThread, OpenProcess, or generic ProcessInjection against known target binaries such as RegSvcs.exe or mobsync.exe. These binaries are frequently abused for proxy execution or living-off-the-land techniques to hide malicious activity.