Non-Slack process posts host recon data to Slack API shortly after launch

Detects suspicious network connectivity where a newly executed process (that is not a browser or Slack) immediately establishes an outbound HTTPS connection to the Slack API. This behavior is indicative of potential malware implants or malicious scripts attempting to perform system reconnaissance and check-in to an attacker-controlled Slack workspace.