PowerShell Steganography Payload Extraction (APT29)
This rule detects the execution of PowerShell commands that utilize .NET's System.Drawing.Bitmap class and the .GetPixel method. This combination is indicative of steganography techniques being used to extract hidden data, often malicious payloads, from image files. This specific pattern has been associated with APT29.
CQL

