BambooToken-style AV enumeration via WMI/SecurityCenter2

Detects the execution of wmic.exe, powershell.exe, or pwsh.exe with command-line arguments related to querying antivirus products or security centers (e.g., AntiVirusProduct, SecurityCenter2). The rule focuses on executions originating from non-standard system paths (e.g., Temp, Users, AppData) or processes that lack a valid code signing signature, which is often indicative of reconnaissance by malicious actors.