Product
This detection monitors for processes executing from temporary or user-writable directories that perform DNS queries to AWS management endpoints, a pattern frequently utilized by post-exploitation tools to bypass CLI-based security controls.