UNK_QuietRacket in-memory .NET payload from decoy HTML via Cloudflare Worker

This rule detects potential fileless execution by correlating network connections to a known suspicious domain (workers.dev) with subsequent PowerShell activity on the same device. The rule specifically looks for processes executing PowerShell commands involving Base64 decoding, ChaCha20 decryption, or Assembly.Load, occurring within a 10-minute window of the network connection.