Best Detection of 2026 Series: Post-Exploitation Shell-to-C2 Pivot

This rule detects potential post-exploitation activity where a web server process spawns a command shell, executes system discovery commands, and immediately initiates an outbound network connection. This behavior is indicative of a web-based exploit leading to interactive command execution and subsequent C2 communication.