Suspicious Screenshot Activity by Remote Management Tools
This rule identifies instances of screen capture events initiated by processes that have previously engaged in network communication with known Remote Management Tool (RMM) domains. By correlating network activity with suspicious endpoint events, it flags potential unauthorized screen scraping performed by tools often abused by attackers for post-compromise reconnaissance.
Microsoft Sentinel (KQL)

