feat(rules): New Process creation via direct syscall rule
#599
+33
−0
Process creation via direct syscall rule
#599