Suspicious curl.exe Download via cmd.exe to User-Writable Path

Detects instances where curl.exe is spawned by cmd.exe or wscript.exe and uses the -o flag to save downloaded files into user-writable directories (e.g., Temp or AppData), a technique often used to stage secondary payloads during the exploitation process.