QUICAgent Go backdoor execution via Windowsupdate.exe from LOCALAPPDATA
Detects the suspicious execution of a file named 'Windowsupdate.exe' located in 'AppData\Local' that is invoked via a command containing 'copy' and '/b'. This behavior is indicative of an attacker attempting to copy or stitch binary files using a masqueraded system process name to evade detection.
Microsoft Sentinel (KQL)

