NightEagle GhostContainer Backdoor via Exchange VIEWSTATE Injection

This rule monitors the Microsoft IIS worker process (w3wp.exe) for the spawning of suspicious child processes often associated with web shell activity, such as command shells (cmd.exe, powershell.exe) or compiler/utility tools (csc.exe, cvtres.exe, rundll32.exe, regsvr32.exe). It further filters for command lines containing Exchange or OWA-related strings, and flags executions containing known web shell indicators (e.g., VIEWSTATE, GhostWebShell, reGeorg).