HVNC Hidden Desktop with Capture/Input APIs from Unsigned Process

This rule detects behavior associated with Hidden Virtual Network Computing (HVNC) implants, which allow remote attackers to interact with a hidden desktop session on a compromised host. The rule specifically looks for processes that perform a sequence of sensitive Windows API calls—CreateDesktopA, SetThreadDesktop, BitBlt/GetDIBits (for screen capture), and SendInput (for input simulation)—when originating from suspicious, unsigned, or non-standard file paths, indicating potential malicious use rather than legitimate software.