OneDrive Initiated Creation of Executable File

Detects the creation of executable or script files within non-system directories that were initiated by the OneDrive sync process. This activity may indicate a user downloading malicious files via a compromised OneDrive account or a malicious payload being synced to the local system.