System Binary Masquerading via Non-Standard Execution Paths

Identifies core Windows subsystem binaries executing from any location other than System32. Binaries such as lsass.exe, winlogon.exe, services.exe and svchost.exe are never legitimately relocated or bundled by third-party software, so execution from an unexpected path indicates an adversary has placed a renamed or copied payload to blend in with normal process listings. The detection uses a composite name-and-path key rather than checking either value independently, which catches relocation while permitting the genuine SysWOW64 copy of svchost.exe. Device paths reported by early-boot processes are normalised rather than excluded so that a genuine hit from a device path still fires. Scope is limited to Windows endpoints via DeviceInfo.