PIVOTPIPE RAT Port-Forward/TCP Beacon Listen Setup (C2 Types 14-17,50,82)

Detects execution of known malicious files that subsequently interact with temporary directory debug logs and establish network listening sockets within a short timeframe. This behavior pattern is characteristic of post-exploitation activity, specifically the staging and operation of listener modules.