Settra ransomware: MeshAgent RMM Deployment (mvtcs.exe) with Mandatory Settra C2/Host Correlation

This rule detects potential unauthorized use of MeshAgent RMM software by correlating process execution events (mvtcs.exe, MeshAgent) with network traffic to specific IP addresses identified as associated with Settra command-and-control infrastructure. It specifically filters for MeshAgent activity and validates the threat by requiring an established network connection to known malicious endpoints.