Disguised MSI Payload Download by Browser_Updater.exe
Detects an initial payload downloader, specifically 'Browser_Updater.exe', initiating network connections to retrieve an MSI payload disguised as an 'iis.jpg' file. This rule identifies suspicious network activity based on the process name and specific network indicators (IP address or URL pattern).
Microsoft Sentinel (KQL)

