Agentic Malware Self-Replication - Autonomous Lateral Movement via Remote Write and Service Creation
This rule detects potentially malicious lateral movement or persistence activities by monitoring the creation or modification of executable files in remote network shares and startup folders, as well as the use of administrative tools like sc.exe or schtasks.exe to create services or tasks. The rule specifically filters out processes signed by Microsoft, focusing on non-standard or unsigned binaries that perform these administrative actions across multiple instances, indicating potential automated lateral propagation.
SentinelOne

