Screening Serpens RAT: AppDomainManager DLL Load from User-Writable Path
This rule detects when an executable or process loads a DLL from commonly writable locations like AppData, Temp, or ProgramData, while also correlating this activity with the loading of .NET CLR runtime components (mscoree.dll, clr.dll, etc.) and potential configuration file modifications. This behavior is indicative of .NET-based injection techniques such as AppDomainManager injection or DLL hijacking targeting .NET applications.
Splunk (SPL)

