Process self-deletion of own executable post-launch (anti-forensic RAT)
Detects a process that deletes its own executable file immediately after launching. This anti-forensic behavior is commonly utilized by remote access trojans (RATs) and other malware to minimize their footprint and evade file-based forensic analysis.
YARA-L

