Silent Radmin install via hidden auto-elevating PowerShell RunAs
This rule detects potentially malicious PowerShell execution patterns involving hidden windows, administrative elevation via 'Start-Process -Verb RunAs', and the targeting or execution of rsetup64.exe within specific system paths. It also flags execution chains where 'net session' commands, often used for discovery or local privilege verification, are piped to null and followed by or initiate the same target executables, suggesting lateral movement or persistence attempts.
Microsoft Sentinel (KQL)

