Log Enumeration or Export Activity by Suspicious Process

Detects the use of system utilities (wevtutil, PowerShell, wmic, etc.) or log-reading tools (grep, tail) for log enumeration or export when executed by processes that are not standard management or monitoring agents. This pattern is commonly associated with adversary efforts to gain situational awareness or identify security logs.