WSL2 Payload Staging via DllHost.exe with No Windows Network Telemetry

Detects potential payload staging activities within a WSL2 environment where a process writes an executable or script to the Windows filesystem using the DllHost.exe (COM Surrogate) proxy. This rule uses process activity on the host to infer the presence of a WSL2 environment (wsl.exe or vmmem) and analyzes the absence of Windows-native network events, which is a characteristic pattern of WSL2-based network activity being hidden from Windows host telemetry.