Charmap.exe outbound connection to AsyncRAT C2 (data/screenshot exfil)
This rule detects the process 'charmap.exe' establishing an outbound network connection to a known AsyncRAT command-and-control (C2) IP address and port. This behavior is indicative of process injection where the legitimate Windows Character Map utility is utilized as a host process for malicious AsyncRAT payload execution.
Microsoft Sentinel (KQL)

