Windows Suspicious QEMU Execution — Detection Rule

Detects execution of the QEMU binary and an image file with the -nographic flag. This causes it to run in the background without any display. This has been observed as a persistence and initial access technique by some threat actors to install a rogue linux virtual machine

Read the full analysis on IntelFusions