Graphalgo detached 'go run .' launch carrying hardcoded TA pubkey material
Detects the execution of the Graphalgo RAT second-stage payload. The rule identifies the spawning of a detached 'go run .' process, which performs an ephemeral key exchange using a hardcoded public key before C2 establishment. It also correlates this activity with parent processes common in software build environments (npm, terraform, go) to differentiate malicious staging from developer activity.
Microsoft Sentinel (KQL)

