XRed Backdoor Masquerading as Synaptics.exe in ProgramData
Detects execution and file activity associated with the XRed backdoor, which masquerades as 'Synaptics.exe' by running from the non-standard 'C:\ProgramData\Synaptics\' directory instead of authorized system paths.
Microsoft Sentinel (KQL)

