Suspicious File Created In PerfLogs — Detection Rule

Detects suspicious file based on their extension being created in "C:\PerfLogs\". Note that this directory mostly contains ".etl" files

Read the full analysis on IntelFusions