AgtaBackup RAT — Masquerading Process
This rule detects the execution of processes that use file names mimicking legitimate security or system services, such as 'Credential Guard.exe' or 'Window Security Health Services.exe'. These names are often used by adversaries for masquerading to evade detection by blending in with legitimate system activity.
Microsoft Sentinel (KQL)

