SloppyRAT Hell's Gate Indirect Syscall Process Injection Chain

This rule detects suspicious process activity in interpreters (ipy.exe, pythonw.exe) or rundll32.exe involving multiple, rapid consecutive calls to sensitive memory management and thread creation functions (e.g., NtAllocateVirtualMemory, NtWriteVirtualMemory, NtCreateThreadEx). The logic specifically monitors for a high frequency of distinct, powerful Windows API calls, which is often indicative of reflective code injection or process hollowing, including techniques like 'Hell's Gate' or those associated with SloppyRAT, and accounts for potential .NET/hostfxr-related execution vectors.