Executable file created in C:\Users\Public directory
This rule monitors for the creation or renaming of executable files (.exe) within the 'Users\Public' directory. This directory is commonly used by adversaries for staging malicious payloads, as it is writable by standard users and often overlooked by security controls.
Microsoft Sentinel (KQL)

