Hello, this rule has been deprecated in july 2023. But related to the question of when this activity would occur; this may occur in situations where a root user catches a reverse shell connection. This is a network event followed by a UID change. This activity is also seen in the port knocking functionality of the open source rootkit dubbed "Reptile". But because the rule was noisy, it was deprecated some time ago.
I hope that helps.
Ruben