Node/Python RAT Spawning Shell for C2-Issued Command Execution

Detects instances where Node.js, Python, or Go processes spawn command shell interpreters (cmd.exe, powershell.exe, etc.). This behavior is often indicative of C2 command execution by malware, such as the Graphalgo RAT, which may use these languages to execute shell-level commands after initial infection or payload execution.