APT36 SHEETCREEP vaultsvc.exe running outside System32/SysWOW64
This rule detects the execution of 'vaultsvc.exe' or executables starting with 'WindowsVault' and ending with '.exe' from suspicious, non-standard directories such as AppData, ProgramData, or Temp. It also flags execution from any non-system path if not in System32, SysWOW64, or Program Files. A known malicious hash for 'vaultsvc.exe' is specifically identified.
Microsoft Sentinel (KQL)

