APT 35 - Charming Kitten - G0059 — Magic Hound | Rogue native IIS module registration (appcmd / gacutil abuse)

This rule detects unauthorized or suspicious registration of native Internet Information Services (IIS) modules. It monitors command-line activity involving common administrative tools used to modify IIS configurations (appcmd.exe) and manage .NET assemblies (gacutil.exe), as well as the execution of specific PowerShell cmdlets like New-WebGlobalModule. Such activities are often indicative of an attacker attempting to establish persistence on a web server by loading malicious modules.