Suspicious Process Spawning from Langflow/Nacos Orchestration Services

Detects suspicious process execution patterns originating from Langflow or Nacos AI orchestration services, including the spawning of sensitive binaries like cmd, powershell, or scripts (python/bash/sh) with suspicious command-line arguments. Additionally, it identifies potential exploitation attempts targeting known-vulnerable API endpoints (code validation and Nacos user authentication).