Multi-Stage BaqiyatLock/Remcos Activity Detection
This rule detects multiple stages of activity associated with BaqiyatLock ransomware and Remcos RAT. It identifies the execution of known BaqiyatLock/Remcos files, attempts to bypass User Account Control (UAC) via ms-settings registry hijack, creation of files with the '.bqtlock' extension indicative of BaqiyatLock encryption, and network communication with 'icanhazip.com' for external IP discovery, which is a common reconnaissance step.
Microsoft Sentinel (KQL)

