Anomalous Binary Execution Path - Pair Probability - Threat Hunting

Surfaces binaries executing from directories they almost never use, by computing pair probabilities across process-start events rather than matching signatures. For each (binary, normalized directory) pair it derives P(A|B) -- of all times this binary ran, what fraction ran from here and ranks ascending, so a binary with thousands of executions appearing once somewhere unexpected rises to the top. Execution paths are normalized first (user profiles, WinSxS versions, GUID/hex/temp directories, version folders) so per-install variance does not manufacture false rarity. Tuned at n_b >= 10000, n_ab <= 5 over a 7-day window; scale n_b with fleet volume. Rarity is not maliciousness: triage by directory writability, whether the binary has a fixed legitimate home, and host count, then pull parent process for anything that clears the bar.

Cortex XDR