Starland RAT System and Antivirus Reconnaissance via CIM/WMI Queries
Detects PowerShell or WMIC commands used by Starland RAT to gather system hardware identifiers, RAM capacity, and installed antivirus products via CIM/WMI queries during victim profiling.
Microsoft Sentinel (KQL)

