or ((match(process, "\.exe(\x22)?\s+tunnel\s?$") and like(process, "%--name %") ...
a C2 channel, accounting for instances where the binary has been renamed.