C2Looper v2 'ls'/'drives' backdoor command execution
Detects the execution of commands 'ls' or 'drives' via command line, which are often used by threat actors for reconnaissance and file/directory enumeration on a compromised host.
Microsoft Sentinel (KQL)

