RedSun: TieringEngineService/Cloud Files API Redirect Defender Write to System32

Detects instances where 'TieringEngineService.exe' or 'MsMpEng.exe' (Windows Defender) create, modify, or rename executable, library, or system files within the 'C:\Windows\System32\' directory. This behavior is highly irregular as these processes should not be authoring binaries in protected system folders, and may indicate process masquerading, unauthorized persistence, or defense evasion.