BotHelper RAT host-control command execution via msedge_proxy.exe
Detects host-control and management tasks (e.g., shutdown, logoff, scheduled task modification) executed as child processes of the msedge_proxy.exe process. This behavior is indicative of the BotHelper malware implant managing infected endpoints.
Microsoft Sentinel (KQL)

