HVNC Operator-Directed Browser Launch to C2 URL via Malicious Parent
Detects the Silver Fox HVNC malware dropper initiating browser instances via the command line to access known malicious C2 domains or infrastructure. The rule specifically monitors for known malicious binaries (UpdateAssistant.exe, AppUpdateHelper.exe, SysMaintenance.exe) launching browsers with suspicious command-line parameters associated with this campaign.
Microsoft Sentinel (KQL)

