Suspicious Files in Default GPO Folder — Detection Rule

Detects the creation of copy of suspicious files (EXE/DLL) to the default GPO storage folder

Read the full analysis on IntelFusions