Prompt-injection content ingestion followed by anomalous agent process execution

This rule detects potential AI agent prompt injection by monitoring email subjects or attachment names for keywords often associated with system instruction overrides. It correlates these potentially malicious emails with subsequent execution of common administrative or script-interpreting binaries (e.g., PowerShell, cmd.exe) on the recipient's device within a one-hour window, suggesting a potential successful hijack of an automated process or AI agent.