Input Injection via AutoHotKey, AutoIt3, or xdotool
Detects the execution of AutoHotkey or AutoIt automation scripts, particularly when these tools spawn suspicious child processes (e.g., cmd.exe, powershell.exe, wmic.exe), initiate commands from non-standard directories (Temp, AppData, Downloads), or run from locations outside of the standard Program Files installation directory.
Microsoft Sentinel (KQL)

