Zscaler ZDX - Suspicious Process Detected via Endpoint Telemetry
This rule monitors process execution events and correlates them against a watchlist of known malicious or suspicious binary names, such as crypto-miners, unauthorized remote access tools, or renamed system utilities (LOLBins) being executed from suspicious locations.
Microsoft Sentinel (KQL)

