QUICAgent Backdoor Execution Detected (Operation QUICSILVER)
Detects the execution of the QUICAgent backdoor (Windowsupdate.exe) from an AppData folder path. The rule monitors for this specific process name, which has been associated with C2 activity including hostname and username enumeration.
Microsoft Sentinel (KQL)

