System Process Masquerading from Non-Standard Directory (T1036.005)
Detects the execution of known critical system processes (e.g., svchost.exe, lsass.exe) from directories other than the standard Windows System32 or SysWOW64 paths. This behavior is indicative of masquerading, where an adversary attempts to evade detection by naming malicious files after legitimate system binaries.
SentinelOne

