ShadowPad TMP payload decryption and injection into wmpnetwk.exe
This rule detects a correlation between the creation of a specific suspicious file named 'A08744D2.tmp' and the subsequent activity of the Windows Media Player Network Sharing Service ('wmpnetwk.exe') within a short time window. This pattern often indicates potentially malicious activity where a temporary file may be used to stage or interact with the service process.
Microsoft Sentinel (KQL)

