Screening Serpens AppDomainManager Hijack + MiniUpdate RAT Azure C2
This rule monitors for indicators associated with MiniUpdate/MiniJunk V2 RAT and general .NET AppDomainManager hijacking. It detects suspicious registry keys (AppDomainManagerAssembly/Type) or environment variable manipulation used to hijack .NET application execution flow. Additionally, it identifies .NET host processes loading DLLs from user-writable directories (e.g., AppData, Temp) and tracks suspicious beaconing patterns to known Azure CDN domains often used by these threats for Command and Control.
Microsoft Sentinel (KQL)

