PE Dropper: Executable Written to Temp/AppData/ProgramData then Executed
Detects the creation of an executable file (.exe, .scr, .com, .pif) in user-writable directories (Temp, AppData, ProgramData) followed by the immediate execution of that same file. This is a common pattern for malware droppers where a file is dropped to disk and subsequently executed to initiate the next stage of an attack.
SentinelOne

