TinyRCT AppDomainManager Injection via chrome_setup (CL-STA-1062)
This rule detects AppDomainManager injection attempts by monitoring for the loading of suspicious DLLs (related to AppDomainManager functionality) by specific processes or from unexpected file paths. The rule specifically targets attempts to hijack the .NET AppDomainManager class by checking against known suspicious filenames and excluding legitimate .NET framework directories, which is a common technique used for arbitrary code execution in the context of a target process.
SentinelOne

