AutoIT interpreter executing BitXOR-based loader script from Temp .ini file
Detects the execution of a potentially malicious, renamed AutoIT interpreter from a temporary directory, where the process command line or associated file activity involves a specific, obfuscated loader script (kojuyn.ini). The rule identifies behavioral patterns consistent with malware staging and execution, including the use of random filenames for both the interpreter and the script, characteristic of loaders using custom string deobfuscation and decryption routines.
Microsoft Sentinel (KQL)

