RMM/RAT tool (TeamViewer etc.) execution from unusual context

This rule detects the execution of common Remote Monitoring and Management (RMM) and remote access tools when initiated from suspicious parent processes (such as browsers, office applications, or command-line interpreters), originating from common writeable directories (e.g., Temp, Downloads), or executed with command-line arguments indicative of silent/unattended installation. This behavior is often associated with initial access, persistence establishment, or unauthorized remote control of a system.