def rule(event):
    if any(
        [
            all(
                [
                    event.deep_get("CommandLine", default="").startswith(
                        '"C:\\Windows\\system32\\wusa.exe"  /quiet C:\\Users\\'
                    ),
                    event.deep_get("CommandLine", default="").endswith(
                        "\\AppData\\Local\\Temp\\update.msu"
                    ),
                    event.deep_get("IntegrityLevel", default="")
                    in ["High", "System", "S-1-16-16384", "S-1-16-12288"],
                ]
            ),
            all(
                [
                    event.deep_get("ParentCommandLine", default="")
                    == '"C:\\Windows\\system32\\dism.exe" /online /quiet /norestart /add-package /packagepath:"C:\\Windows\\system32\\pe386" /ignorecheck',
                    event.deep_get("IntegrityLevel", default="") in ["High", "System"],
                    "C:\\Users\\" in event.deep_get("CommandLine", default=""),
                    "\\AppData\\Local\\Temp\\" in event.deep_get("CommandLine", default=""),
                    "\\dismhost.exe {" in event.deep_get("CommandLine", default=""),
                    event.deep_get("Image", default="").endswith("\\DismHost.exe"),
                ]
            ),
        ]
    ):
        return True
    return False
