Flowise MCP node_options Case-Bypass RCE — Child Process and Marker File

Detects exploitation attempts against the Flowise Model Context Protocol (MCP) environment, specifically targeting the node_options case-sensitivity bypass (CVE-2026-20182). The rule monitors for malicious node child process spawning, command line injection via the --require flag, suspicious file creation (flowise_marker.txt), and unauthorized outbound network connections from the Flowise process.