AsyncRAT HKCU Run Key Persistence with Non-Standard Port C2
This rule detects potential persistence via Registry Run keys (T1547.001) where a value is added pointing to a file in an AppData or Temp directory, followed by a successful outbound network connection from a process located in those same directories. This behavior is indicative of malware or an adversary establishing persistence and immediately reaching out to a command-and-control (C2) server.
Microsoft Sentinel (KQL)

