TokenGrabber Stealer: In-Memory StolenData ZIP Staging Pre-Exfiltration
Detects a behavioral chain where a process establishes persistence using a 'WindowsUpdate' Registry Run key or a scheduled task, followed within five minutes by an outbound network connection from the same process. The rule specifically excludes cases where a ZIP file was written to disk, identifying potential in-memory staging for exfiltration.
Microsoft Sentinel (KQL)

