RtkNGUI64.exe Realtek Backdoor Spawns cmd.exe (CMD= Tasking)
This rule detects malicious activity associated with the RtkNGUI64.exe backdoor, which masquerades as a legitimate Realtek Audio process. It identifies when this process spawns cmd.exe for command execution or interacts with 'tempcache.tmp' files, indicating potential C2 tasking and persistence via WMI event consumers.
Microsoft Sentinel (KQL)

