UNC6240 ShinyHunter MeshAgent PeopleSoft implant drop in /tmp beaconing to UNC6240 infrastructure
This rule detects the execution of the MeshAgent remote administration tool from a temporary directory followed by a network connection to known malicious infrastructure within a 15-minute window. This behavior is indicative of unauthorized remote access setup or C2 activity using a legitimate remote management utility.
Microsoft Sentinel (KQL)

