Falcon is generating detections for a malicious file evil.exe with varying filepaths on several hosts as end users attempt to execute the file.Which query can be used to proactively hunt where the file exists prior to the user executing it?