Polymorphic Executable Detected - Multiple Hashes Same Path (T1027.014)

Detects the creation of multiple executable files (.exe or .dll) within a 6-hour window in non-standard directories (outside of Windows or Program Files). The rule identifies scenarios where a single filename has three or more distinct SHA256 hashes associated with it on a specific device, which may indicate iterative malware delivery, obfuscation techniques, or persistence mechanism testing.