Process Hollowing and Doppelganging - Anomalous Parent and Non-Standard Path
Detects critical Windows system processes (svchost.exe, lsass.exe, csrss.exe, wininit.exe, winlogon.exe, spoolsv.exe) that are either spawned by unexpected parent processes or reside in non-standard directories. This behavior is indicative of potential masquerading, process injection, or malicious persistence attempts.
Microsoft Sentinel (KQL)

