WMI Lateral Movement via wmiprvse.exe Spawning Shell

Detects instances where the WMI Provider Host (wmiprvse.exe) spawns suspicious child processes such as cmd.exe, powershell.exe, or rundll32.exe, which are correlated with inbound network connections on ports 135 (RPC/DCOM) or 445 (SMB). This behavior is characteristic of lateral movement techniques used by tools like Impacket's wmiexec.