1C:Enterprise malicious dump load (1C-Shell.dt / KRAUD)
This rule detects potential unauthorized activity originating from 1C Enterprise processes (rphost.exe, rmngr.exe, 1cv8.exe, 1cv8c.exe) when involving specific keywords like '1C-Shell.dt' or 'KRAUD'. It specifically monitors for the subsequent execution of local user account management commands (net user, net localgroup, New-LocalUser) by the 1C server process (rphost.exe) within an hour of the initial suspicious event.
Microsoft Sentinel (KQL)

