Suspicious PowerShell SendKeys Injection
Detects a hidden PowerShell process dynamically loading the Windows Forms assembly to inject base64-encoded keystrokes into foreground applications. This technique is used by the SStar Agent RAT for its remote 'type' functionality.
Microsoft Sentinel (KQL)

