Suspicious Launch of Character Map from Temp Directory
Detects the execution of the Windows Character Map utility (charmap.exe) when launched from a user-writable Temp directory by a non-standard parent process. This pattern is commonly associated with malware, such as AsyncRAT, attempting to leverage legitimate system tools to evade detection or facilitate malicious chains.
Microsoft Sentinel (KQL)

