DCRAT dropped by rockstargames.exe batch script into Default user Local Settings
Detects rockstargames.exe dropping a batch script or executing binaries directly from C:\Users\Default\Local Settings, specifically targeting the execution pattern associated with DCRAT (UserOOBEBroker.exe masquerading).
Splunk (SPL)

