TokenGrabber Builder: Silent Pip Install of Infostealer Dependencies

Detects multiple, rapid execution sequences of Python or PIP utilities using the 'install' flag with specific common library names often used in reconnaissance or malicious activity. This activity is monitored by looking for repetitive installations of targeted packages within a short timeframe on the same endpoint, which may indicate automated tool deployment or preparation for malicious operations.