RustDesk/Cloudflared Service Install via PowerShell for C2 Tunneling
Detects the installation of RustDesk or Cloudflared as a persistent Windows service, initiated by a PowerShell script. This behavior is indicative of unauthorized use of remote access or tunneling tools, often observed in intrusion activity such as Bumblebee, AdaptixC2, or Akira ransomware to facilitate persistence and establish reverse tunnels through firewalls.
Sigma

