Potentially Suspicious Execution From Parent Process In Public Folder — Detection Rule
Detects a potentially suspicious execution of a parent process located in the "\Users\Public" folder executing a child process containing references to shell or scripting binaries and commandlines.