BeepRAT: TCC In-Memory Shellcode Execution with AMSI/ETW Bypass

Detects anomalous behavior associated with the 'tcc.exe' executable, which is often leveraged by the BeepRAT loader for malicious operations. The rule monitors for suspicious process start flags ('-nostdlib', '-run'), execution from unconventional locations (outside of standard Program Files), the spawning of common shell processes (cmd.exe, powershell.exe, etc.), and unsolicited outbound network connectivity. This rule effectively flags potential loaders or backdoor activity originating from this binary.