OneDriveUpdater Executed from Non-Standard Location
Detects execution of OneDriveUpdater.exe from C:\ProgramData, which may represent a masqueraded binary attempting to impersonate legitimate Microsoft software. This could indicate an attempt at defense evasion or persistence by an attacker.
Microsoft Sentinel (KQL)

