Starland RAT Secondary Payload Execution from TEMP Folder
Detects the execution of binaries (exe, dll, msi) or scripts via rundll32/msiexec from the user's Local AppData Temp directory. This behavior is commonly associated with staging and executing secondary payloads by malware such as the Starland RAT, which frequently drops and runs its payloads from these locations to evade detection.
Microsoft Sentinel (KQL)

