Malicious Script Persistence in Startup Folder
This rule detects potential persistence mechanisms where a suspicious batch file (.bat) is placed within the Windows Startup folder and subsequently executed using command-line arguments that include specific file extensions like .exe and .ini. This behavior is indicative of malware, such as remote access trojans (RATs), attempting to maintain persistence upon system reboot.
Microsoft Sentinel (KQL)

