bc26970596
This rule is subject to false negatives for *nix distros which alias /bin to /usr/bin. By using endswith we can catch dd usage for either /bin or /usr/bin.