MovieReaper Stage-3 msedge.exe Masquerade from Telemetry Folder
Detects the MovieReaper Stage-3 module which masquerades as Microsoft Edge (msedge.exe) within the C:\ProgramData\Windows\Telemetry directory. The detection focuses on suspicious process execution from this directory and identifies instances where the process respawns itself, suggesting malicious activity post-UAC bypass.
Splunk (SPL)

