Suspicious rundll32.exe Loading DLL from Writable Path (T1574.002)
Detects the execution of rundll32.exe from common user-writable or temporary directories (Temp, AppData, ProgramData), which is a common technique used by malware to execute payloads while avoiding security monitoring of standard system directories.
SentinelOne

