Registry Persistence with DLL Hijacking

Detects potential DLL hijacking persistence by identifying modifications to registry values containing executable or library files that point to locations outside standard Windows system directories (System32 or SysWow64), subsequently joined with the execution of legitimate binary proxies known to be abused for side-loading like rundll32.exe or regsvcs.exe.