Suspicious PowerShell SendKeys Injection (SStar Agent)
Detects a hidden PowerShell process dynamically loading the Windows Forms assembly to inject base64-encoded keystrokes into foreground applications. This behavior is associated with the SStar Agent RAT's remote 'type' functionality.
Microsoft Sentinel (KQL)

