Fileless self-relocation to /dev/shm/.journal masquerading as systemd-journald
Detects a suspicious pattern where a process creates a file in /dev/shm/, unlinks it, and re-executes itself from /proc/self/fd/ while manipulating the process name to masquerade as the systemd-journald daemon. This behavior is indicative of fileless execution techniques used by malware to maintain a presence while blending in with legitimate system processes.
Microsoft Sentinel (KQL)

