Phishing Abuses RMM Tools: Disguised Utility Staged via ScreenConnect
This rule detects the execution of potentially malicious binaries masquerading as legitimate Windows utilities (e.g., Windows Update, Defender, or Phone Link) from within a ScreenConnect temporary directory. This behavior is indicative of a phishing attack where an adversary uses remote access tools to stage and execute malicious payloads on a victim's system.
Microsoft Sentinel (KQL)

