AD Recon via AdFind/SharpHound/BloodHound Execution

Detects the execution of known Active Directory reconnaissance tools, specifically AdFind and SharpHound/BloodHound. These tools are commonly used by adversaries to enumerate domain objects, users, computers, groups, and trusts, which are essential precursors to further lateral movement and privilege escalation within a domain environment.