Suspicious File Write to System Directory
This rule detects the creation or modification of executable files (.exe, .dll, .sys) within critical Windows system directories (C:\Windows\System32\ or C:\Windows\SysWOW64\). Such activity can indicate an attempt to establish persistence, elevate privileges, or inject malicious code into legitimate system processes.
Microsoft Sentinel (KQL)

