DllHost.exe WSL2-Proxied Executable File Creation in High-Risk Directories

Detects instances where DllHost.exe creates executable or script files within common writable directories such as Users, ProgramData, or Windows\Temp. This behavior is often indicative of an adversary staging malicious payloads or scripts to facilitate further execution.