APT 35 - Charming Kitten - G0059 — Magic Hound | Suspicious file writes into IIS/Exchange web paths (webshells, rogue modules)

This rule detects the creation or modification of suspicious files (extensions associated with web shells or modules, such as .aspx, .ashx, .asmx, .dll, or .config) within common Microsoft IIS and Exchange web directories. It correlates these file events with process activity initiated by common web server or management processes (e.g., w3wp.exe, powershell.exe) and filters out trusted files (Microsoft-signed), known administrative update activity, and files with a broader footprint in the environment to identify potentially malicious, low-prevalence artifacts.