Serpens AppDomainManager Hijacking via Suspicious .NET Config File Write
Detects the creation or modification of '.config' or '.exe.config' files within commonly user-writable directories such as AppData, Temp, Downloads, or Desktop. These files are often used by .NET applications to define behavior, and attackers may manipulate them to perform activities such as assembly redirection, loading malicious DLLs, or altering security settings for elevated processes.
Microsoft Sentinel (KQL)

