Suspicious Python Environment Hook File Creation
Detects the creation or modification of Python configuration files (.pth, sitecustomize.py, usercustomize.py) within site-packages or dist-packages directories when not initiated by recognized Python package managers. Such files can be abused to achieve arbitrary code execution upon Python interpreter startup, a common method for persistence or local privilege escalation in Python environments.
Microsoft Sentinel (KQL)

