DLL Side-Loading from User-Writable Directory by Signed Binary
Detects when a signed process loads a DLL from a non-standard, user-writable directory (e.g., Temp, Downloads, Public folders). This is a common indicator of DLL hijacking or side-loading, where a legitimate signed application is leveraged to load a malicious library from a compromised location.
SentinelOne

