GhostContainer Backdoor Deployment on Exchange via w3wp.exe
Detects the deployment of the GhostContainer backdoor, which masquerades as an IIS server component loaded within w3wp.exe. The rule monitors for command-line arguments associated with web shells and known exploitation tools like reGeorg, indicating an attempt to maintain persistence following an Exchange server compromise.
YARA-L

