TGR-STA-1030/UNC6619 Open-Source C2 Framework Execution from Writable Dirs

Detects the execution of known Command and Control (C2) frameworks such as Sliver, Havoc, SparkRAT, or VShell from common suspicious temporary or staging directories (temp, tmp, appdata, programdata). This rule monitors process creation events to identify the presence of these unauthorized remote access tools.