Potential TrueConf Server Exploitation, Web-Shell Deployment, or Installer Replacement
This KQL detects attack used TCP port 4307 for unauthenticated access and replaced public\js\locale.php with a web shell that provided persistent remote access.
Microsoft Sentinel (KQL)

