Sauron Loader Shellcode Injection into attrib.exe

Detects the execution of attrib.exe spawned by known Sauron Loader process names (rnpkeys.exe, rnp.exe, or tdwp.exe). The rule flags instances where attrib.exe is executed without its typical command-line arguments (file attribute flags), suggesting it is being used as a surrogate process for injected C2-tasked shellcode.