DllHost.exe WSL2-Proxied Executable File Creation in High-Risk Directories
Detects instances where DllHost.exe creates executable or script files within common writable directories such as Users, ProgramData, or Windows\Temp. This behavior is often indicative of an adversary staging malicious payloads or scripts to facilitate further execution.
Splunk (SPL)

