Batch file dropped into Startup folder for persistence (AsyncRAT)
Detects the creation of a .bat file in the Windows Startup directory, followed by the execution of a command process from a temporary location using a specific command line pattern. This behavior is indicative of persistent malware or a dropper attempting to execute an initial payload upon user logon.
Microsoft Sentinel (KQL)

