Suspicious Lineage (Anomalies)
outlook.exe→winword.exe→powershell.exe(Classic Phishing / Macro Execution)httpd.exeornginx→cmd.exe(Web Server Exploitation / Web Shell)services.exe→Rundll32.exewithout legitimate arguments.- Any unsigned binary spawning built-in system administration tools.