Execution of Suspicious Batch File Linked to AsyncRAT
This rule detects the execution of a specific batch file named 'Right-click to open Invoice Details.bat', or execution of a batch file matching a known malicious SHA256 hash associated with AsyncRAT distribution campaigns.
Microsoft Sentinel (KQL)

