MATCHBOIL payload and config staging in disguised LOCALAPPDATA and Public paths
Detects payload staging activity associated with threat actor UAC-0099, correlating the creation or modification of executable/DLL files in disguised LocalAppData directories with decoy images or library configuration files within a one-hour window.
Microsoft Sentinel (KQL)

