Process Execution From A Potentially Suspicious Folder — Detection Rule

Detects a potentially suspicious execution from an uncommon folder.

Read the full analysis on IntelFusions