MovieReaper Four-Stage Chain: Loader to C2 to Telemetry Payload
This rule detects a multi-stage malicious behavior chain: the execution of a suspected loader (identified by hash or specific mutex), followed by network communication to a known C2 domain or IP, and concluded by the placement of a file in the Windows Telemetry folder (typically mimicking msedge.exe). The events are correlated within a short time window (2 hours between each stage) on the same device.
Microsoft Sentinel (KQL)

