Lazarus Group Supply Chain: Update Path File Creation with Outbound Network Activity
This rule detects a sequence of suspicious activities: the creation or modification of an executable file (.exe or .dll) within a directory path containing update-related keywords, followed by the execution of a file in that same location, and culminating in an outbound network connection from that process. This pattern is characteristic of a software supply chain compromise or an adversary deploying a malicious payload via a fake or compromised update mechanism.
Microsoft Sentinel (KQL)

