Nuitka-Compiled RAT Launcher chost.exe or loader.py Execution
This rule detects potential Remote Access Trojan (RAT) activity by identifying specific indicators associated with Nuitka-compiled binaries, specifically the 'chost.exe' filename or paths containing 'win-driver-xd7d'. Additionally, it monitors for suspicious Python-based loader executions ('loader.py') initiated from temporary directories, which is a common persistence or execution technique for such malware.
SentinelOne

