PrettyPrague Avast Sandbox exploit escalating to SYSTEM

Detects the execution or initiation of a process named 'PrettyPrague.exe' while running with SYSTEM level privileges (AccountSid: S-1-5-18) from directories associated with Avast antivirus software. This activity is indicative of potential privilege escalation or malicious activity masquerading within legitimate security software paths.