Docker Desktop malware campaign
This rule detects suspicious network connections to known malicious URLs associated with a Docker Desktop malware campaign. It also identifies instances where 'DockerDesktop.exe' is executed or present in unusual file paths, suggesting potential masquerading or unauthorized deployment outside of its standard installation directory. The rule is broken into three parts: network events, file events, and process events. The network part looks for connections to specific malicious domains. The file and process parts look for 'DockerDesktop.exe' in folders other than the assumed legitimate installation path, indicating potential malicious activity.
Microsoft Sentinel (KQL)

