Java/Tomcat Process Spawning Discovery Commands (Fileless Web Shell)

Detects the execution of discovery or credential access utilities (e.g., whoami, net, reg, ldapsearch) spawned by Java-based server processes like java.exe or tomcat.exe. This activity is often indicative of an attacker leveraging a vulnerable web application to perform reconnaissance or credential harvesting on the host system.