Suspicious DLL Load from Writable Directories
Detects the loading of DLLs with suspicious names ('hook.dll', 'inject.dll', 'logger.dll', 'loader.dll') from common user-writable directories such as 'Temp', 'AppData', or 'Downloads'. These patterns are frequently associated with malware loaders, persistence mechanisms, or unauthorized code injection attempts.
Microsoft Sentinel (KQL)

