Screening Serpens - setup.exe DLL Sideload from User-Writable Directory
This rule monitors for processes named 'setup.exe' executing from user-writable directories (e.g., AppData, Downloads, Temp) that load unsigned or non-Microsoft DLLs from the same suspicious directories. This pattern is commonly associated with DLL side-loading or malicious installation attempts where a process attempts to load illegitimate code from local user space.
Microsoft Sentinel (KQL)

