Yeah, they could have moved processes before execing the shell. Detecting "Firefox + Shell" is quite easy and standard, even in existing SIEMs.
Detecting "arbitrary program + shell" is at least moderately more difficult.
It's the attacker's dilemma though. They only need to trip one alarm to trigger IR.