Deepfake Capture During Live Call - Screen and Audio Exfiltration Precursor

This rule detects processes that load sensitive Windows multimedia and graphics modules (mmdevapi.dll, avrt.dll, magnification.dll, dxgi.dll) which are commonly utilized for audio recording and screen capturing. The rule filters out known legitimate applications (e.g., Teams, Zoom, Web browsers) and trusted software publishers. It further identifies potential suspicious activity by flagging processes originating from common staging paths like 'Temp', 'Downloads', or 'ProgramData' and instances where the process image is unsigned.