Python Embed ZIP Downloaded to Public Dir via Batch Script
Detects the download and subsequent extraction of the Python embeddable zip package to directories under 'C:\Users\Public'. This activity is consistent with techniques used by threat actors, such as APT37, to establish a covert Python runtime environment on a compromised host for further malicious operations.
Sigma

