APT28 CovenantGrunt DLL Load from ProgramData into explorer.exe
Detects instances where explorer.exe loads a DLL file from within C:\ProgramData. This behavior is often associated with adversary activity attempting to hide malicious modules in directories that may have permissive write access or are excluded from routine scans, including techniques used by Covenant frameworks or C2 agents.
Microsoft Sentinel (KQL)

