Go Agent ADB-shell persistence, Doze-exemption, and package-tampering command ch

Detects a specific sequence of Android Debug Bridge (ADB) commands typical of malicious Android agents, specifically those running with elevated privileges (UID 2000/shell/root). The rule identifies combinations of permission grants, battery optimization bypasses, and package tampering (disabling or uninstalling) occurring within the same context.