CL-STA-1062 SoftEther VPN Disguised as VMware Process (T1572/T1036)
Detects anomalous network communication patterns and file system changes indicative of SoftEther VPN usage, particularly when linked to processes masquerading as VMware or communicating with known malicious C2 infrastructure. The rule monitors for network connections on common SoftEther ports, connections to specific command-and-control IP addresses, and the creation of SoftEther configuration files like 'hamcore.se2' or 'vpn_bridge.config'.
Microsoft Sentinel (KQL)

