Ransomware/Lateral Movement Following ScreenConnect Session Activity
Detects anomalous post-exploitation behaviors such as mass file modifications, lateral movement (SMB/RDP), or persistence mechanisms (scheduled tasks/services) following ScreenConnect client session activity. This behavior is indicative of potential exploitation of ScreenConnect to deploy ransomware or move laterally within the network.
YARA-L

