PowerShell WriteAllBytes dropping AsyncRAT payload trio to Temp
Detects the use of PowerShell's 'WriteAllBytes' method to write a file to the user's Local AppData Temp directory, immediately followed by the creation of a known or suspicious executable file in that same location. This pattern is commonly indicative of a stage in a fileless-style malware attack or automated payload delivery.
Microsoft Sentinel (KQL)

