SilverFox No-Referrer Hidden-Anchor EXE Download Evasion
Detects instances where a new executable file (.exe) is written to the file system following a download event. The rule specifically looks for scenarios where the download URL ends in .exe or is a direct download link, while flagging cases where the referrer is empty or missing, often indicative of direct downloads from C2 infrastructure or scripts rather than user-initiated browser navigation.
CQL

