WSL2 Payload Staging: DllHost.exe Drops Executable in High-Risk Directory

Detects instances where DllHost.exe (COM Surrogate) creates executable or script files in high-risk, user-writable directories. This activity is indicative of potential exploitation of the Windows Subsystem for Linux (WSL2) filesystem proxy, where a Linux process running within WSL2 writes files to the Windows host filesystem (/mnt/c/), resulting in the file creation event being attributed to the DllHost.exe COM surrogate on the Windows side.