Unsigned DLL Side-Loading via Microsoft Office Applications

Detects when common Microsoft Office applications (Word, Excel, PowerPoint, Outlook) load a DLL file from suspicious or user-writable locations such as AppData, Downloads, Documents, or Temp folders. The rule specifically alerts on DLLs that are unsigned or where the loading process itself is unsigned, which is a common indicator of side-loading or malicious library injection.