Process Injection via Cross Process from AppData/Temp/ProgramData into System Process

Detects cross-process activity where an unsigned executable residing in common user-writable directories (AppData, Temp, ProgramData) attempts to interact with or inject into sensitive system processes (explorer.exe, svchost.exe, notepad.exe). This behavior is characteristic of malicious process injection attempts.