Signed Canon/Stardock binary launched by msiexec from user-writable path (sidelo
Detects the execution of known Canon or Stardock software binaries (COTFileReadApp.exe, DeElevate64.exe) when spawned by msiexec.exe from non-standard locations such as Temp or AppData directories. This pattern is indicative of potential defense evasion, where adversaries leverage legitimate software to proxy execution or potentially perform side-loading activities.
Sigma

