TokenGrabber Stealer: Chained Persistence and Wi-Fi Credential Theft Commands
Detects a suspicious sequence of events where a process creates a scheduled task named 'WindowsUpdate' followed by execution of 'netsh' commands to dump wireless profiles or clear keys within a 15-minute window. This behavioral pattern is often associated with credential-stealing malware attempting to establish persistence and harvest sensitive information.
Microsoft Sentinel (KQL)

