Detects the creation of copy of suspicious files (EXE/DLL) to the default GPO storage folder
Read the full analysis on IntelFusions