APT28 CovenantGrunt Fileless .NET Load in explorer.exe with filen.io C2
This rule detects the suspicious initialization of the Common Language Runtime (CLR) components (mscoree.dll, clr.dll, or oleaut32.dll) within the explorer.exe process, followed closely by an outbound HTTPS connection to filen.io domains. This pattern is indicative of fileless .NET-based C2 implants, such as those generated by the Covenant framework, executing within the context of a legitimate Windows shell process.
Microsoft Sentinel (KQL)

