Sauron Loader Chunked Screenshot Exfiltration Burst to C2
This rule detects potentially malicious C2 communication by monitoring high-frequency HTTP POST requests from the 'rnpkeys.exe' process. It aggregates network events over 30-second windows and flags activity exceeding a threshold of 5 POST requests directed at known suspicious domains or specific high-port network destinations, which is characteristic of beaconing or data exfiltration activity.
Cortex XDR

