Hidden Cobalt Strike Beacon Injection Attempt
This rule detects command line patterns associated with Cobalt Strike Beacon injection, specifically looking for indicators of 'beacon.dll', 'beacon.exe', or 'injection' strings being executed by suspicious parent processes such as explorer.exe, svchost.exe, or winlogon.exe. This activity is indicative of post-exploitation behavior and potential lateral movement or persistence attempts.
Microsoft Sentinel (KQL)

