Hello
In Windows 10 Enterprise 22 H2, a strange path in TargetFilename sometimes appears in Sysmon logs:
TargetFilename: C:\Users\P310C~1.ZNO\AppData\Local\Temp\7b542cd6-d613-4e52-bfdf-b80fe911ff30.tmp
And in the next event, the path is normal:
TargetFilename...