C2Looper pld.exe dropped directly in LocalAppData root
Detects the creation or renaming of a file named 'pld.exe' within the AppData Local directory. This path is frequently used by malware to masquerade as legitimate applications and establish persistence while avoiding scrutiny.
Microsoft Sentinel (KQL)

