OpenSUpdater – Suspicious Nested Installer Execution
Detects the execution of a file named 'setup.exe' from suspicious user-writable directories (Temp, Downloads, AppData) when the command line arguments contain keywords associated with archive utilities like 7-Zip or Foobar2000. This pattern is indicative of a 'nested installer' technique where legitimate software utilities are leveraged to extract or execute malicious payloads.
Microsoft Sentinel (KQL)

