Cobalt Strike Named Pipe & Reflective Injection Indicators

Detects known Cobalt Strike default named pipe naming conventions and cross-process reflective DLL injection activities into common Windows host processes such as rundll32.exe, svchost.exe, and others. This rule monitors for suspicious named pipe creation events and process memory manipulation patterns indicative of beacon behavior and post-exploitation injection.