SStar Agent Windows Temp CMD Execution
Detects the SStar Agent malware executing remote shell commands by creating and executing ephemeral batch files. The malware creates a file named sstar-*.cmd in the %TEMP% directory and executes it using cmd.exe.
Microsoft Sentinel (KQL)

