PowerShell Spawns MSI/EXE Installer for RMM Agent
This rule detects instances where PowerShell is used to download or execute remote monitoring and management (RMM) tools or remote access software binaries (e.g., AnyDesk, TeamViewer, Atera). This pattern is often indicative of an adversary attempting to establish persistent remote access to a compromised system after initial intrusion.
SentinelOne

