RDP Session Hijacking via tscon.exe Session Switching (T1563.002)

Detects the execution of 'tscon.exe', a Windows utility used to control Remote Desktop sessions. The rule specifically alerts when 'tscon.exe' is executed with parameters indicative of session hijacking (such as '/dest:') or when it is invoked by suspicious processes or under SYSTEM privileges, which are characteristic of RDP session hijacking techniques used for privilege escalation and lateral movement.