PrettyPrague Avast Sandbox exploit escalating to SYSTEM
Detects the execution or initiation of a process named 'PrettyPrague.exe' while running with SYSTEM level privileges (AccountSid: S-1-5-18) from directories associated with Avast antivirus software. This activity is indicative of potential privilege escalation or malicious activity masquerading within legitimate security software paths.
Microsoft Sentinel (KQL)

