US-First RMM phishing campaign: RMM-as-RAT install via msiexec of GoTo/LogMeIn/ITarian MSI post VBS chain
Detects the silent installation of remote monitoring and management (RMM) software using 'msiexec.exe' initiated by scripting engines (powershell.exe, wscript.exe, or cscript.exe). The rule targets installations occurring in user-writable directories, such as Temp or Downloads, which are common staging locations for malicious droppers, while excluding known legitimate software deployment paths.
Microsoft Sentinel (KQL)

