AutoIt Script Execution of Suspicious .ini Payloads
Detects the execution of AutoIt-related processes from temporary directories that are attempting to load or execute suspicious .ini configuration files or specifically named executables, which is a common delivery mechanism for malware such as AsyncRAT.
Microsoft Sentinel (KQL)

