Windows Mock Trusted Directory MSC File Creation — Detection Rule
Detects the creation of MSC files within a "C:\Windows \System32" directory. Due to how Windows parses paths, the space causes an execution flow hijack and a malicious file will be executed instead of the standard Windows Files.