Casbaneiro infection marker folder created in %PUBLIC%
This rule detects the creation of files within the '\Users\Public\' directory that follow a specific, suspicious dynamic naming pattern: 'DeviceName@4AccountName'. Attackers often use the Public directory for staging malicious tools or payloads. This naming convention, which includes both the hostname and the executing account name, is highly indicative of automated, malicious activity or custom staging scripts.
Microsoft Sentinel (KQL)

