WSL2 Staged Payload Execution from Public/Temp/ProgramData via DllHost or Shell Parent

Detects the execution of short-named executable binaries from common staging directories (Users\Public, Windows\Temp, ProgramData) where the parent process is DllHost.exe, explorer.exe, or cmd.exe. This pattern is indicative of WSL2 being used to stage and execute payloads, where DllHost.exe is leveraged to proxy file operations from the WSL2 environment to the Windows host, potentially bypassing certain security controls.