ThreatStack definitely does this, utilizing the OS-exposed auditing frameworks. There are probably open source alternatives as well, but I rely extensively on TS for server-level threat detection.
You don't need to make calls to external programs to make good use of an RCE vulnerability like this.