Files With System Process Name In Unsuspected Locations — Detection Rule

Detects the creation of an executable with a system process name in folders other than the system ones (System32, SysWOW64, etc.). It is highly recommended to perform an initial baseline before using this rule in production.

Read the full analysis on IntelFusions