StealC .NET Anti-Debugging via Debugger.IsAttached/FailFast
This rule detects PowerShell command lines that include .NET API calls typically used for anti-debugging and anti-analysis evasion, such as 'Debugger.IsAttached', 'Debugger.IsLogging', 'CheckRemoteDebuggerPresent', and 'Environment.FailFast'. These checks are common in malicious loaders and implants to determine if the process is being analyzed or monitored, allowing the malware to modify its behavior accordingly.
Sigma

