Keyboard hook install followed by keylog file staging in Temp/AppData
Detects suspicious use of Windows API functions (SetWindowsHookEx) often associated with keylogging, correlated with the presence of temporary staging files in common directories (e.g., Temp, AppData). The rule excludes known legitimate applications that frequently utilize system hooks.
Microsoft Sentinel (KQL)

