Windowsupdate.exe masquerade executed from user LOCALAPPDATA
Detects the execution of a process named 'Windowsupdate.exe' from within the user's Local AppData directory. This pattern is indicative of masquerading, where malware attempts to evade detection by mimicking the legitimate Windows Update executable, a technique observed in the Operation QUICSILVER campaign.
Microsoft Sentinel (KQL)

