GhostContainer Backdoor File Drop in Exchange/IIS Directories

Detects the creation of suspicious DLL or ASPX files within Microsoft Exchange or IIS directories that are associated with the GhostContainer backdoor, commonly used by the NightEagle threat actor for maintaining persistence.