I wonder if those dreaded endpoint security programs (ie, ClownStrike) would have picked up on this type of attack.
I guess this type of traffic would only get flagged if attackers were skids (ie, re-using known RATs)
I guess this type of traffic would only get flagged if attackers were skids (ie, re-using known RATs)