Rogue ScreenConnect client install with known malicious instance IDs
This rule detects the execution, file creation, or registry modification associated with specific ScreenConnect (ConnectWise Control) installation artifacts that align with known suspicious deployment patterns. It monitors for binaries and configuration artifacts that may indicate the unauthorized installation or persistence of remote administration tools.
Microsoft Sentinel (KQL)

